PT-2025-51673 · Linux · Linux Kernel

Published

2025-11-11

·

Updated

2026-03-07

·

CVE-2025-68260

CVSS v2.0

4.6

Medium

AV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.18 and later Android Binder driver (Rust implementation)
Description The first Common Vulnerabilities and Exposures (CVE) has been assigned to Rust code within the Linux kernel. The issue, identified as CVE-2025-68260, affects the Android Binder driver rewrite and is caused by a race condition in an unsafe block. This race condition can lead to memory corruption of the prev and next pointers in a linked list, potentially causing a kernel panic or system crash. The vulnerability is a result of a flaw in handling concurrency within the unsafe code, where the language's safety guarantees do not apply, and developers must manually ensure correctness. The issue occurs when threads concurrently access and modify a linked list, leading to data corruption. The vulnerability does not currently allow for remote code execution or privilege escalation, and is assessed as a Denial of Service (DoS) issue.
Recommendations For kernel maintainers, ensure upstream patches for CVE-2025-68260 are applied if shipping kernels with the Rust Binder driver enabled (CONFIG ANDROID BINDER IPC RUST).

Exploit

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2026-00911
CVE-2025-68260
OPENSUSE-SU-2025:15836-1
OPENSUSE-SU-2026:10301-1

Affected Products

Linux Kernel