cbcvebase.
CVE-2025-68188
published 2025-12-16

CVE-2025-68188: In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair…

PriorityP420high7.8
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= cf1ef3f0719b4dcb74810ed507e2a2540f9811b4 < bc2b881a0896c111c1041d8bb1f92a3b3873ace5bc2b881a0896c111c1041d8bb1f92a3b3873ace5
linuxlinux>= cf1ef3f0719b4dcb74810ed507e2a2540f9811b4 < 06da08d9355bf8e2070459bbedbe372ccc02cc0e06da08d9355bf8e2070459bbedbe372ccc02cc0e
linuxlinux>= cf1ef3f0719b4dcb74810ed507e2a2540f9811b4 < b62a59c18b692f892dcb8109c1c2e653b2abc95cb62a59c18b692f892dcb8109c1c2e653b2abc95c
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.12.0 < 6.12.586.12.58
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

vendor_msrc7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.