cbcvebase.
CVE-2025-68378
published 2025-12-24

CVE-2025-68378: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check in __bpf_get_stackid() Syzkaller reported a KASAN…

PriorityP426high7.2
EPSS
0.16%
5.9th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check in __bpf_get_stackid() Syzkaller reported a KASAN slab-out-of-bounds write in __bpf_get_stackid() when copying stack trace data. The issue occurs when the perf trace contains more stack entries than the stack map bucket can hold, leading to an out-of-bounds write in the bucket's data array.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.110 < 5.115.11
linuxlinux>= 5.15.33 < 5.165.16
linuxlinux>= 5.16.19 < 5.175.17
linuxlinux>= 5.17.2 < 5.185.18
linuxlinux>= ee2a098851bfbe8bcdd964c0121f4246f00ff41e < d1f424a77b6bd27b361737ed73df49a0158f1590d1f424a77b6bd27b361737ed73df49a0158f1590
linuxlinux>= ee2a098851bfbe8bcdd964c0121f4246f00ff41e < 2a008f6de163279deffd488c1deab081bce5667c2a008f6de163279deffd488c1deab081bce5667c
linuxlinux>= ee2a098851bfbe8bcdd964c0121f4246f00ff41e < 4669a8db976c8cbd5427fe9945f12c5fa5168ff34669a8db976c8cbd5427fe9945f12c5fa5168ff3
linuxlinux>= ee2a098851bfbe8bcdd964c0121f4246f00ff41e < 23f852daa4bab4d579110e034e4d513f7d49084623f852daa4bab4d579110e034e4d513f7d490846
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.18.0 < 6.12.636.12.63
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.