CVE-2025-68341 — Race Condition within a Thread in Linux
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateApr 6
Description
In the Linux kernel, the following vulnerability has been resolved:
veth: reduce XDP no_direct return section to fix race
As explain in commit fa349e396e48 ("veth: Fix race with AF_XDP exposing
old or uninitialized descriptors") for veth there is a chance after
napi_complete_done() that another CPU can manage start another NAPI
instance running veth_pool(). For NAPI this is correctly handled as the
napi_schedule_prep() check will prevent multiple instances from getting
scheduled, but for the r…
Affected Packages5 packages
▶CVEListV5linux/linux401cb7dae8130fd34eb84648e02ab4c506df7d5e — c1ceabcb347d1b0f7e70a7384ec7eff3847b7628+3