cbcvebase.
CVE-2025-68221
published 2025-12-16

CVE-2025-68221: In the Linux kernel, the following vulnerability has been resolved: mptcp: fix address removal logic in mptcp_pm_nl_rm_addr Fix inverted WARN_ON_ONCE condition…

PriorityP420high7.2
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix address removal logic in mptcp_pm_nl_rm_addr Fix inverted WARN_ON_ONCE condition that prevented normal address removal counter updates. The current code only executes decrement logic when the counter is already 0 (abnormal state), while normal removals (counter > 0) are ignored.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.10-1 (forky)linux 6.17.10-1 (forky)
linuxlinux
linuxlinux>= 63611391850850bf27f81afb0d0b6d1237a34006 < f7d953c38245c0e9d8e268fb6a9e524602fb44ecf7d953c38245c0e9d8e268fb6a9e524602fb44ec
linuxlinux>= 63611391850850bf27f81afb0d0b6d1237a34006 < 92e239e36d600002559074994a545fcfac9afd2d92e239e36d600002559074994a545fcfac9afd2d
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.15.0 < 6.17.106.17.10

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_redhat5.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.