cbcvebase.
CVE-2025-68182
published 2025-12-16

CVE-2025-68182: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link() This code frees "link"…

PriorityP339high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link() This code frees "link" by calling kfree_rcu(link, rcu_head) and then it dereferences "link" to get the "link->fw_id". Save the "link->fw_id" first to avoid a potential use after free.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= d1e879ec600f9b3bdd253167533959facfefb17b < 5b4a239c9f94e1606435f1842fc6fd426d607dbb5b4a239c9f94e1606435f1842fc6fd426d607dbb
linuxlinux>= d1e879ec600f9b3bdd253167533959facfefb17b < 77e67d5daaf155f7d0f99f4e797c4842169ec19e77e67d5daaf155f7d0f99f4e797c4842169ec19e
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.15.0 < 6.17.86.17.8
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.