CVE-2025-68294 — Resource Injection in Linux
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 89.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 6
Description
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: ensure vectored buffer node import is tied to notification
When support for vectored registered buffers was added, the import
itself is using 'req' rather than the notification io_kiocb, sr->notif.
For non-vectored imports, sr->notif is correctly used. This is important
as the lifetime of the two may be different. Use the correct io_kiocb
for the vectored buffer import.
Affected Packages5 packages
▶CVEListV5linux/linux23371eac7d9a9bca5360cfb3eb3aa08648ee7246 — 14459281e027f23b70885c1cc1032a71c0efd8d7+2