CVE-2025-38733 (GCVE-0-2025-38733)
Vulnerability from cvelistv5
Published
2025-09-05 17:20
Modified
2026-08-05 12:04
Summary
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Do not map lowcore with identity mapping Since the identity mapping is pinned to address zero the lowcore is always also mapped to address zero, this happens regardless of the relocate_lowcore command line option. If the option is specified the lowcore is mapped twice, instead of only once. This means that NULL pointer accesses will succeed instead of causing an exception (low address protection still applies, but covers only parts). To fix this never map the first two pages of physical memory with the identity mapping.
Impacted products
Vendor Product Version
Linux Linux Version: 32db401965f165f7c44447d0508097f070c8f576
Version: 32db401965f165f7c44447d0508097f070c8f576
Version: 32db401965f165f7c44447d0508097f070c8f576
Version: 0b99d0e17d6a73a0526f92bc6b54b2b95e67a31d
Version: 6.10.11   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/s390/boot/vmem.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "30bf5728bb217a6d1ba73f44094c9b9c6bc9a567",
              "status": "affected",
              "version": "32db401965f165f7c44447d0508097f070c8f576",
              "versionType": "git"
            },
            {
              "lessThan": "1d7864acd497cb468a998d44631f84896f885e85",
              "status": "affected",
              "version": "32db401965f165f7c44447d0508097f070c8f576",
              "versionType": "git"
            },
            {
              "lessThan": "93f616ff870a1fb7e84d472cad0af651b18f9f87",
              "status": "affected",
              "version": "32db401965f165f7c44447d0508097f070c8f576",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0b99d0e17d6a73a0526f92bc6b54b2b95e67a31d",
              "versionType": "git"
            },
            {
              "lessThan": "6.11",
              "status": "affected",
              "version": "6.10.11",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/s390/boot/vmem.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "lessThan": "6.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.44",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.44",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.4",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17",
                  "versionStartIncluding": "6.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.10.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Do not map lowcore with identity mapping\n\nSince the identity mapping is pinned to address zero the lowcore is always\nalso mapped to address zero, this happens regardless of the relocate_lowcore\ncommand line option. If the option is specified the lowcore is mapped\ntwice, instead of only once.\n\nThis means that NULL pointer accesses will succeed instead of causing an\nexception (low address protection still applies, but covers only parts).\nTo fix this never map the first two pages of physical memory with the\nidentity mapping."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The defective mapping is created by the s390 boot-time page table setup and is leveraged by triggering a kernel NULL pointer dereference, which requires the ability to execute code/syscalls on the affected system. No network protocol handler is involved in the flawed mapping itself.\nAC:L - The identity base is pinned to zero in all default (non-DEBUG_VM) builds, and the lowcore layout at virtual address 0 is a fixed, publicly documented ABI, so the read/write offsets are fully deterministic with no race or memory-layout uncertainty for the attacker to lose.\nPR:L - An ordinary unprivileged local user can reach kernel code paths containing NULL-dereference bugs (many via syscalls, ioctls, or user namespaces); no capability or administrative privilege is needed to convert those into lowcore accesses.\nUI:N - The mapping is established unconditionally at boot and the dereference is triggered directly by the attacker\u0027s own syscall; no action by any other user is required.\nS:U - The corrupted resource is the kernel\u0027s own per-CPU lowcore within the same security authority as the kernel; no hypervisor, IOMMU, or guest/host boundary is crossed.\nC:H - NULL reads now succeed and return lowcore contents, disclosing the stack canary (0x240), current_task (0x340), kernel_stack (0x348), kernel_asce (0x388), and percpu_offset (0x3b8); a large identity page at address 0 additionally exposes the first megabyte of physical memory, and hijacking user_asce or current_task escalates this to arbitrary kernel memory read.\nI:H - Writes to offsets outside low address protection\u0027s 0-511/4096-4607 windows silently corrupt return_psw (0x290), current_task (0x340), the kernel/async/nodat/mcck stack pointers, restart_fn (0x370), and kernel_asce/user_asce, giving kernel control-flow hijack and full privilege escalation instead of a fault.\nA:H - Silent corruption of the lowcore \u2014 the CPU\u0027s PSW, stack pointer, ASCE, and current-task state \u2014 produces immediate kernel panics or undefined CPU behavior, and the missing exception means faults that would have been a contained oops instead destabilize the whole system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:04:23.788Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/30bf5728bb217a6d1ba73f44094c9b9c6bc9a567"
        },
        {
          "url": "https://git.kernel.org/stable/c/1d7864acd497cb468a998d44631f84896f885e85"
        },
        {
          "url": "https://git.kernel.org/stable/c/93f616ff870a1fb7e84d472cad0af651b18f9f87"
        }
      ],
      "title": "s390/mm: Do not map lowcore with identity mapping",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-38733",
    "datePublished": "2025-09-05T17:20:33.075Z",
    "dateReserved": "2025-04-16T04:51:24.033Z",
    "dateUpdated": "2026-08-05T12:04:23.788Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…