cbcvebase.
CVE-2025-68374
published 2025-12-24

CVE-2025-68374: In the Linux kernel, the following vulnerability has been resolved: md: fix rcu protection in md_wakeup_thread We attempted to use RCU to protect the pointer…

PriorityP421high7.2
EPSS
0.17%
6.6th percentile
In the Linux kernel, the following vulnerability has been resolved: md: fix rcu protection in md_wakeup_thread We attempted to use RCU to protect the pointer 'thread', but directly passed the value when calling md_wakeup_thread(). This means that the RCU pointer has been acquired before rcu_read_lock(), which renders rcu_read_lock() ineffective and could lead to a use-after-free.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= 4469315439827290923fce4f3f672599cabeb366 < 21989cb5034c835b212385a2afadf279d8069da021989cb5034c835b212385a2afadf279d8069da0
linuxlinux>= 4469315439827290923fce4f3f672599cabeb366 < a4bd1caf591faeae44cb10b6517e7dacb5139bdaa4bd1caf591faeae44cb10b6517e7dacb5139bda
linuxlinux>= 4469315439827290923fce4f3f672599cabeb366 < f98b191f78124405294481dea85f8a22a3eb0a59f98b191f78124405294481dea85f8a22a3eb0a59
linuxlinux>= 4469315439827290923fce4f3f672599cabeb366 < 0dc76205549b4c25705e54345f211b9f66e018a00dc76205549b4c25705e54345f211b9f66e018a0
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.5.0 < 6.12.636.12.63
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_msrc5.5MEDIUM
vendor_redhat4.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.