CVE-2025-68234 — Linux vulnerability
19 documents7 sources
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 89.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 6
Description
In the Linux kernel, the following vulnerability has been resolved:
io_uring/cmd_net: fix wrong argument types for skb_queue_splice()
If timestamp retriving needs to be retried and the local list of
SKB's already has entries, then it's spliced back into the socket
queue. However, the arguments for the splice helper are transposed,
causing exactly the wrong direction of splicing into the on-stack
list. Fix that up.
Affected Packages5 packages
▶CVEListV5linux/linux9e4ed359b8efad0e8ad4510d8ad22bf0b060526a — c85d2cfc5e24e6866b56c7253fd4e1c7db35986c+2