CVE-2025-68317 — Improper Validation of Consistency within Input in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
io_uring/zctx: check chained notif contexts
Send zc only links ubuf_info for requests coming from the same context.
There are some ambiguous syz reports, so let's check the assumption on
notification completion.
Affected Packages6 packages
▶CVEListV5linux/linux6fe4220912d19152a26ce19713ab232f4263018d — aaafd17d3f4be2c15539359a5b4bfa00237f687f+3
🔴Vulnerability Details
8📋Vendor Advisories
7Red Hat▶
kernel: Linux kernel: Denial of Service via improper handling of io_uring notification contexts↗2025-12-16