cbcvebase.
CVE-2025-68218
published 2025-12-16

CVE-2025-68218: In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix lockdep WARN due to partition scan work Blktests test cases nvme/014…

PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.46%
37.5th percentile
In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix lockdep WARN due to partition scan work Blktests test cases nvme/014, 057 and 058 fail occasionally due to a lockdep WARN. As reported in the Closes tag URL, the WARN indicates that a deadlock can happen due to the dependency among disk->open_mutex, kblockd workqueue completion and partition_scan_work completion. To avoid the lockdep WARN and the potential deadlock, cut the dependency by running the partition_scan_work not by kblockd workqueue but by nvme_wq.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1f021341eef41e77a633186e9be5223de2ce5d48 < ef4ab2a8abe554379e10303ae86f7c501336ba0def4ab2a8abe554379e10303ae86f7c501336ba0d
linuxlinux>= 1f021341eef41e77a633186e9be5223de2ce5d48 < b03eb63288a8ffe3adfb34e68309c8e2edb06d0bb03eb63288a8ffe3adfb34e68309c8e2edb06d0b
linuxlinux>= 1f021341eef41e77a633186e9be5223de2ce5d48 < 6d87cd5335784351280f82c47cc8a657271929c36d87cd5335784351280f82c47cc8a657271929c3
linuxlinux>= 4a57f42e5ed42cb8f1beb262c4f6d3e698939e4e < e2a897ad5f538d314955c747a0a2edb184fcdecde2a897ad5f538d314955c747a0a2edb184fcdecd
linuxlinux>= 6.1.118 < 6.1.1596.1.159
linuxlinux>= 6.11.9 < 6.126.12
linuxlinux>= 6.6.62 < 6.6.1186.6.118
linuxlinux>= 60de2e03f984cfbcdc12fa552f95087c35a05a98 < 89456dab7ba5ab63d60945440926673a3205e82989456dab7ba5ab63d60945440926673a3205e829
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 6.1.1596.1.159
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.12.0 < 6.17.106.17.10
linuxlinux_kernel>= 6.2.0 < 6.6.1186.6.118
linuxlinux_kernel>= 6.7.0 < 6.12.606.12.60
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.2HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.