Linux Kernel Rust Code Sees Its First CVE Vulnerability (phoronix.com)
(Thursday December 18, 2025 @11:46AM (BeauHD)
from the safe-until-it-isn't dept.)
Longtime Linux developer Greg Kroah-Hartman [1]announced that the Linux kernel has [2]received its first CVE tied to Rust code . Phoronix reports:
> This first CVE ( [3]CVE-2025-68260 ) for Rust code in the Linux kernel pertains to the Android Binder rewrite in Rust. There is a race condition that can occur due to some noted unsafe Rust code. That code can lead to memory corruption of the previous/next pointers and in turn cause a crash. This CVE for the possible system crash is for Linux 6.18 and newer since the introduction of the Rust Binder driver. At least though it's just a possible system crash and not any more serious system compromise with remote code execution or other more severe issues.
[1] https://social.kernel.org/notice/B1JLrtkxEBazCPQHDM
[2] https://www.phoronix.com/news/First-Linux-Rust-CVE
[3] https://lore.kernel.org/linux-cve-announce/2025121614-CVE-2025-68260-558d@gregkh/T/#u
> This first CVE ( [3]CVE-2025-68260 ) for Rust code in the Linux kernel pertains to the Android Binder rewrite in Rust. There is a race condition that can occur due to some noted unsafe Rust code. That code can lead to memory corruption of the previous/next pointers and in turn cause a crash. This CVE for the possible system crash is for Linux 6.18 and newer since the introduction of the Rust Binder driver. At least though it's just a possible system crash and not any more serious system compromise with remote code execution or other more severe issues.
[1] https://social.kernel.org/notice/B1JLrtkxEBazCPQHDM
[2] https://www.phoronix.com/news/First-Linux-Rust-CVE
[3] https://lore.kernel.org/linux-cve-announce/2025121614-CVE-2025-68260-558d@gregkh/T/#u