cbcvebase.
CVE-2025-68284
published 2025-12-16

CVE-2025-68284: In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() The len field…

PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.51%
40.7th percentile
In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() The len field originates from untrusted network packets. Boundary checks have been added to prevent potential out-of-bounds writes when decrypting the connection secret or processing service tickets. [ idryomov: changelog ]

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 < f22c55a20a2d9ffbbac57408d5d488cef8201e9df22c55a20a2d9ffbbac57408d5d488cef8201e9d
linuxlinux>= 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 < 8dfcc56af28cffb8f25fb9be37b3acc61f2a3d098dfcc56af28cffb8f25fb9be37b3acc61f2a3d09
linuxlinux>= 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 < ccbccfba25e9aa395daaea156b5e7790910054c4ccbccfba25e9aa395daaea156b5e7790910054c4
linuxlinux>= 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 < 5ef575834ca99f719d7573cdece9df2fe2b724245ef575834ca99f719d7573cdece9df2fe2b72424
linuxlinux>= 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 < 6920ff09bf911bc919cd7a6b7176fbdd1a6e68506920ff09bf911bc919cd7a6b7176fbdd1a6e6850
linuxlinux>= 285ea34fc876aa0a2c5e65d310c4a41269e2e5f2 < 7fce830ecd0a0256590ee37eb65a39cbad3d64fc7fce830ecd0a0256590ee37eb65a39cbad3d64fc
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.2.0 < 6.6.1196.6.119
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-azure-5.15
ubuntulinux-xilinx

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat6.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.