Executive brief
A vulnerability in the Linux kernel for ARM64 systems could allow a local attacker to cause a system crash or potentially gain unauthorized access. The issue occurs during specific internal operations where the system switches between different tasks or handles hardware interrupts. If these operations are interrupted at the wrong moment, the system's internal memory protections can become corrupted, leading to unpredictable behavior or a complete system failure.
Technical details
A race condition exists in the ARM64 implementation of cpu_switch_to() and call_on_irq_stack() where stack pointer (SP) manipulation and Shadow Call Stack (SCS) pointer updates are not performed atomically. On systems with CONFIG_SHADOW_CALL_STACK enabled, an SError or Debug Exception occurring between these updates can cause the interrupt handler to save an incorrect SCS pointer, clobbering the task's stack. This risk is significantly increased on systems using CONFIG_ARM64_PSEUDO_NMI, where pseudo-NMIs can frequently interrupt these critical sections. An attacker with local access could potentially exploit this to trigger kernel panics or achieve arbitrary code execution by corrupting return addresses. The fix involves masking DAIF (Debug, Abort, IRQ, FIQ) flags during these transitions to ensure atomicity.
Affected products
- Linux Linux arm64 architecture versions prior to fixed stable releases
Timeline
- 2025-07-18: disclosed: Initial patch submission
- 2025-08-01: patched: Merged into stable kernel trees
- 2025-08-22: advisory: CVE-2025-38670 published
References
- https://git.kernel.org/stable/c/0f67015d72627bad72da3c2084352e0aa134416b
- https://git.kernel.org/stable/c/407047893a64399f2d2390ff35cc6061107d805d
- https://git.kernel.org/stable/c/708fd522b86d2a9544c34ec6a86fa3fc23336525
- https://git.kernel.org/stable/c/9433a5f437b0948d6a2d8a02ad7a42ab7ca27a61
- https://git.kernel.org/stable/c/a6b0cb523eaa01efe8a3f76ced493ba60674c6e6
- https://git.kernel.org/stable/c/d42e6c20de6192f8e4ab4cf10be8c694ef27e8cb
- https://git.kernel.org/stable/c/f7e0231eeaa33245c649fac0303cf97209605446