PT-2025-25841 · Glibc+5 · Glibc+5

Anubis

·

Published

2025-03-06

·

Updated

2026-04-20

·

CVE-2025-38067

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the rseq feature. The issue occurs when the rseq cs field is non-zero during registration, which can cause a segfault on return to user-space if the value stored in the rseq cs field does not point to a valid struct rseq cs. The problem arises because some older versions of glibc reuse the rseq area of previous threads without clearing the rseq cs field and will terminate the process if the rseq registration fails in a secondary thread.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

AZL-63977
AZL-72710
BDU:2025-14933
CVE-2025-38067
DLA-4327-1
DLA-4328-1
DSA-5973-1
DSA-5975-1
ECHO-F1C3-C3D6-AAD2
OESA-2025-1823
OESA-2025-1824
OESA-2025-1870
RHSA-2025:20095
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7789-1
USN-7789-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu
Glibc