Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-38067

5.5 · MEDIUM
Published Jun 18, 2025 linux EPSS 0.50% (41th pctl)

Overview

CVE-2025-38067 is a medium-severity vulnerability affecting linux linux_kernel. It was published on June 18, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

rseq: Fix segfault on registration when rseq_cs is non-zero

The rseq_cs field is documented as being set to 0 by user-space prior to

registration, however this is not currently enforced by the kernel. This

can result in a segfault on return to user-space if the value stored in

the rseq_cs field doesn't point to a valid struct rseq_cs.

The correct solution to this would be to fail the rseq registration when

the rseq_cs field is non-zero. However, some older versions of glibc

will reuse the rseq area of previous threads without clearing the

rseq_cs field and will also terminate the process if the rseq

registration fails in a secondary thread. This wasn't caught in testing

because in this case the leftover rseq_cs does point to a valid struct

rseq_cs.

What we can do is clear the rseq_cs field on registration when it's

non-zero which will prevent segfaults on registration and won't break

the glibc versions that reuse r

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.18, < 5.10.240 Affected

Frequently Asked Questions

What is CVE-2025-38067?

CVE-2025-38067 is a medium-severity vulnerability affecting linux linux_kernel. It was published on June 18, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2025-38067?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2025-38067?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-38067?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-38067 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.