CVE-2025-68260: rust_binder: fix race condition on death_list
In the Linux kernel, the following vulnerability has been resolved:
rustbinder: fix race condition on deathlist
Rust Binder contains the following unsafe operation:
// SAFETY: A NodeDeath is never inserted into the death list // of any node other than its owner, so it is either in this // death list or in no death list. unsafe { nodeinner.deathlist.remove(self) };
This operation is unsafe because when touching the prev/next pointers of a list element, we have to ensure that no other thread is also touching them in parallel. If the node is present in the list that remove is called on, then that is fine because we have exclusive access to that list. If the node is not in any list, then it's also ok. But if it's present in a different list that may be accessed in parallel, then that may be a data race on the prev/next pointers.
And unfortunately that is exactly what is happening here. In Node::release, we:
1. Take the lock. 2. Move all items to a local list on the stack. 3. Drop the lock. 4. Iterate the local list on the stack.
Combined with threads using the unsafe remove method on the original list, this leads to memory corruption of the prev/next pointers. This leads to crashes like this one:
Unable to handle kernel paging request at virtual address 000bb9841bcac70e Mem abort info: ESR = 0x0000000096000044 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000044, ISS2 = 0x00000000 CM = 0, WnR = 1, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [000bb9841bcac70e] address between user and kernel address ranges Internal error: Oops: 0000000096000044 [#1] PREEMPT SMP google-cdd 538c004.gcdd: context saved(CPU:1) item - logkevents is disabled Modules linked in: ... rustbinder CPU: 1 UID: 0 PID: 2092 Comm: kworker/1:178 Tainted: G S W OE 6.12.52-android16-5-g98debd5df505-4k #1 f94a6367396c5488d635708e43ee0c888d230b0b Tainted: [S]=CPUOUTOFSPEC, [W]=WARN, [O]=OOTMODULE, [E]=UNSIGNEDMODULE Hardware name: MUSTANG PVT 1.0 based on LGA (DT) Workqueue: events RNvXs6NtCsdfZWD8DztAw6kernel9workqueueINtNtNtB74sync3arc3ArcNtNtCs8QPsHWIn21X16rustbindermain7process7ProcessEINtB515WorkItemPointerKy0E3runB13 [rustbinder] pstate: 23400005 (nzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : RNvXs3NtCs8QPsHWIn21X16rustbindermain7processNtB57ProcessNtNtCsdfZWD8DztAw6kernel9workqueue8WorkItem3run+0x450/0x11f8 [rustbinder] lr : RNvXs3NtCs8QPsHWIn21X16rustbindermain7processNtB57ProcessNtNtCsdfZWD8DztAw6kernel9workqueue8WorkItem3run+0x464/0x11f8 [rustbinder] sp : ffffffc09b433ac0 x29: ffffffc09b433d30 x28: ffffff8821690000 x27: ffffffd40cbaa448 x26: ffffff8821690000 x25: 00000000ffffffff x24: ffffff88d0376578 x23: 0000000000000001 x22: ffffffc09b433c78 x21: ffffff88e8f9bf40 x20: ffffff88e8f9bf40 x19: ffffff882692b000 x18: ffffffd40f10bf00 x17: 00000000c006287d x16: 00000000c006287d x15: 00000000000003b0 x14: 0000000000000100 x13: 000000201cb79ae0 x12: fffffffffffffff0 x11: 0000000000000000 x10: 0000000000000001 x9 : 0000000000000000 x8 : b80bb9841bcac706 x7 : 0000000000000001 x6 : fffffffebee63f30 x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000000 x2 : 0000000000004c31 x1 : ffffff88216900c0 x0 : ffffff88e8f9bf00 Call trace: RNvXs3NtCs8QPsHWIn21X16rustbindermain7processNtB57ProcessNtNtCsdfZWD8DztAw6kernel9workqueue8WorkItem3run+0x450/0x11f8 [rustbinder bbc172b53665bbc815363b22e97e3f7e3fe971fc] processscheduledworks+0x1c4/0x45c workerthread+0x32c/0x3e8 kthread+0x11c/0x1c8 retfromfork+0x10/0x20 Code: 94218d85 b4000155 a94026a8 d10102a0 (f9000509) ---[ end trace 0000000000000000 ]---
Thus, modify Node::release to pop items directly off the original list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68260?
CVE-2025-68260 has been classified with a high severity due to its potential for a race condition impacting system stability.
How do I fix CVE-2025-68260?
To fix CVE-2025-68260, update your Linux kernel to the latest stable version where the vulnerability has been resolved.
Which versions of Linux kernel are affected by CVE-2025-68260?
CVE-2025-68260 affects specific versions of the Linux kernel prior to the fix, particularly those utilizing Rust Binder.
What impact does CVE-2025-68260 have on my system?
CVE-2025-68260 may allow for unexpected behavior or instability in systems using the Rust Binder functionality in the Linux kernel.
Is CVE-2025-68260 related to Rust programming language features?
Yes, CVE-2025-68260 specifically involves Rust Binder, which integrates Rust programming language features into the Linux kernel.