PT-2026-2863 · Linux+2 · Linux Kernel+2

Published

2025-01-01

·

Updated

2026-05-11

·

CVE-2025-71102

CVSS v2.0

5.5

Medium

VectorAV:A/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the scs magic function within the shadow call stack (SCS) implementation. The function requires a 'void *' variable but receives a 'struct task struct *' instead. This incorrect parameter passing occurs when using task scs(tsk) as input to scs magic. When the CONFIG DEBUG STACK USAGE configuration is enabled, the scs check usage function scans an incorrect memory range, potentially leading to inaccurate stack usage reporting and, in rare cases, a kernel crash if scs magic(tsk) is greater than scs magic(task scs(tsk)). The issue primarily affects developers and testers debugging stack usage with the specified configuration enabled and does not impact normal production systems. The vulnerable function is scs magic().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-03368
CVE-2025-71102
ECHO-4059-4B5F-D07E
MGASA-2026-0017
MGASA-2026-0018
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8243-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu