PT-2025-25841 · Glibc+5 · Glibc+5
Anubis
·
Published
2025-03-06
·
Updated
2026-04-20
·
CVE-2025-38067
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, related to the rseq feature. The issue occurs when the rseq cs field is non-zero during registration, which can cause a segfault on return to user-space if the value stored in the rseq cs field does not point to a valid struct rseq cs. The problem arises because some older versions of glibc reuse the rseq area of previous threads without clearing the rseq cs field and will terminate the process if the rseq registration fails in a secondary thread.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu
Glibc