PT-2025-25808 · Linux+5 · Linux Kernel+5

Published

2025-04-10

·

Updated

2026-05-26

·

CVE-2025-38033

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the version that includes the fix for this issue
Description A vulnerability in the Linux kernel has been resolved. The issue occurs when calling core::fmt::write() from Rust code while FineIBT is enabled, resulting in a kernel panic. This happens because core::fmt::write() calls core::fmt::rt::Argument::fmt(), which currently has CFI disabled, causing a Control Protection exception. The vulnerability makes Rust currently incompatible with FineIBT. The issue is expected to be fixed in Rust 1.88.0, scheduled for release on 2025-06-26.
Recommendations For Linux kernel versions prior to the fixed version, consider disabling FineIBT until a patch is available. As a temporary workaround, avoid using Rust code that calls core::fmt::write() until the issue is resolved. Once Rust 1.88.0 is released, update to this version or later to fix the issue. At the moment, there is no information about a newer Linux kernel version that contains a fix for this vulnerability.

Exploit

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08920
CVE-2025-38033
ECHO-0851-4D85-A544
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Rust
Ubuntu