- Joined
- Dec 19, 2005
- Messages
- 17,701
"This first CVE for Rust code in the Linux kernel pertains to the Android Binder rewrite in Rust. There is a race condition that can occur due to some noted unsafe Rust code. That code can lead to memory corruption of the previous/next pointers and in turn cause a crash.
This CVE for the possible system crash is for Linux 6.18 and newer since the introduction of the Rust Binder driver. At least though it's just a possible system crash and not any more serious system compromise with remote code execution or other more severe issues.
More details on CVE-2025-68260 via the Linux CVE mailing list."
Source: https://www.phoronix.com/forums/for...el-rust-code-sees-its-first-cve-vulnerability
This CVE for the possible system crash is for Linux 6.18 and newer since the introduction of the Rust Binder driver. At least though it's just a possible system crash and not any more serious system compromise with remote code execution or other more severe issues.
More details on CVE-2025-68260 via the Linux CVE mailing list."
Source: https://www.phoronix.com/forums/for...el-rust-code-sees-its-first-cve-vulnerability