cbcvebase.
CVE-2025-68227
published 2025-12-16

CVE-2025-68227: In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix proto fallback detection with BPF The sockmap feature allows bpf syscall from…

PriorityP421high7.8
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix proto fallback detection with BPF The sockmap feature allows bpf syscall from userspace, or based on bpf sockops, replacing the sk_prot of sockets during protocol stack processing with sockmap's custom read/write interfaces. ''' tcp_rcv_state_process() syn_recv_sock()/subflow_syn_recv_sock() tcp_init_transfer(BPF_SOCK_OPS_PASSIVE_ESTABLISHED_CB) bpf_skops_established sk_prot to compare with the native sk_prot, but this is incorrect when sockmap is used, as we may incorrectly set sk->sk_socket->ops. This fix uses the more generic sk_family for the comparison instead. Additionally, this also prevents a WARNING from occurring: result from ./scripts/decode_stacktrace.sh: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 337 at net/mptcp/protocol.c:68 mptcp_stream_accept \ (net/mptcp/protocol.c:4005) Modules linked in: ... PKRU: 55555554 Call Trace: do_accept (net/socket.c:1989) __sys_accept4 (net/socket.c:2028 net/socket.c:2057) __x64_sys_accept (net/socket.c:2067) x64_sys_call (arch/x86/entry/syscall_64.c:41) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) RIP: 0033:0x7f87ac92b83d ---[ end trace 0000000000000000 ]---

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < 92c4092fe012ecdfa5fb05d394f1c1d8f91ad81c92c4092fe012ecdfa5fb05d394f1c1d8f91ad81c
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < 7ee8f015eb47907745e2070184a8ab1e442ac3c47ee8f015eb47907745e2070184a8ab1e442ac3c4
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < 344974ea1a3ca30e4920687b0091bda4438cebdb344974ea1a3ca30e4920687b0091bda4438cebdb
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < 037cc50589643342d69185b663ecf9d26cce91e8037cc50589643342d69185b663ecf9d26cce91e8
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < 9b1980b6f23fa30bf12add19f37c7458625099eb9b1980b6f23fa30bf12add19f37c7458625099eb
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < 1a0d5c74af9b6ba9ffdf1172de5a1a6df5922a001a0d5c74af9b6ba9ffdf1172de5a1a6df5922a00
linuxlinux>= 0b4f33def7bbde1ce2fea05f116639270e7acdc7 < c77b3b79a92e3345aa1ee296180d1af4e7031f8fc77b3b79a92e3345aa1ee296180d1af4e7031f8f
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.7.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.106.17.10
linuxlinux_kernel>= 6.2.0 < 6.6.1186.6.118
linuxlinux_kernel>= 6.7.0 < 6.12.606.12.60
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-azure-5.15

CVSS provenance

osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.