{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-38733",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T04:51:24.033Z",
        "datePublished": "2025-09-05T17:20:33.075Z",
        "dateUpdated": "2026-08-05T12:04:23.788Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:04:23.788Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Do not map lowcore with identity mapping\n\nSince the identity mapping is pinned to address zero the lowcore is always\nalso mapped to address zero, this happens regardless of the relocate_lowcore\ncommand line option. If the option is specified the lowcore is mapped\ntwice, instead of only once.\n\nThis means that NULL pointer accesses will succeed instead of causing an\nexception (low address protection still applies, but covers only parts).\nTo fix this never map the first two pages of physical memory with the\nidentity mapping."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The defective mapping is created by the s390 boot-time page table setup and is leveraged by triggering a kernel NULL pointer dereference, which requires the ability to execute code/syscalls on the affected system. No network protocol handler is involved in the flawed mapping itself.\nAC:L - The identity base is pinned to zero in all default (non-DEBUG_VM) builds, and the lowcore layout at virtual address 0 is a fixed, publicly documented ABI, so the read/write offsets are fully deterministic with no race or memory-layout uncertainty for the attacker to lose.\nPR:L - An ordinary unprivileged local user can reach kernel code paths containing NULL-dereference bugs (many via syscalls, ioctls, or user namespaces); no capability or administrative privilege is needed to convert those into lowcore accesses.\nUI:N - The mapping is established unconditionally at boot and the dereference is triggered directly by the attacker's own syscall; no action by any other user is required.\nS:U - The corrupted resource is the kernel's own per-CPU lowcore within the same security authority as the kernel; no hypervisor, IOMMU, or guest/host boundary is crossed.\nC:H - NULL reads now succeed and return lowcore contents, disclosing the stack canary (0x240), current_task (0x340), kernel_stack (0x348), kernel_asce (0x388), and percpu_offset (0x3b8); a large identity page at address 0 additionally exposes the first megabyte of physical memory, and hijacking user_asce or current_task escalates this to arbitrary kernel memory read.\nI:H - Writes to offsets outside low address protection's 0-511/4096-4607 windows silently corrupt return_psw (0x290), current_task (0x340), the kernel/async/nodat/mcck stack pointers, restart_fn (0x370), and kernel_asce/user_asce, giving kernel control-flow hijack and full privilege escalation instead of a fault.\nA:H - Silent corruption of the lowcore — the CPU's PSW, stack pointer, ASCE, and current-task state — produces immediate kernel panics or undefined CPU behavior, and the missing exception means faults that would have been a contained oops instead destabilize the whole system."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "arch/s390/boot/vmem.c"
                    ],
                    "versions": [
                        {
                            "version": "32db401965f165f7c44447d0508097f070c8f576",
                            "lessThan": "30bf5728bb217a6d1ba73f44094c9b9c6bc9a567",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "32db401965f165f7c44447d0508097f070c8f576",
                            "lessThan": "1d7864acd497cb468a998d44631f84896f885e85",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "32db401965f165f7c44447d0508097f070c8f576",
                            "lessThan": "93f616ff870a1fb7e84d472cad0af651b18f9f87",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b99d0e17d6a73a0526f92bc6b54b2b95e67a31d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6.10.11",
                            "lessThan": "6.11",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "arch/s390/boot/vmem.c"
                    ],
                    "versions": [
                        {
                            "version": "6.11",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.11",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.44",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.16.4",
                            "lessThanOrEqual": "6.16.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.17",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.11",
                                    "versionEndExcluding": "6.12.44"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.11",
                                    "versionEndExcluding": "6.16.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.11",
                                    "versionEndExcluding": "6.17"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10.11"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/30bf5728bb217a6d1ba73f44094c9b9c6bc9a567"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1d7864acd497cb468a998d44631f84896f885e85"
                },
                {
                    "url": "https://git.kernel.org/stable/c/93f616ff870a1fb7e84d472cad0af651b18f9f87"
                }
            ],
            "title": "s390/mm: Do not map lowcore with identity mapping",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}