cbcvebase.
CVE-2025-68743
published 2025-12-24

CVE-2025-68743: In the Linux kernel, the following vulnerability has been resolved: mshv: Fix create memory region overlap check The current check is incorrect; it only checks…

PriorityP420high7.2
EPSS
0.16%
5.7th percentile
In the Linux kernel, the following vulnerability has been resolved: mshv: Fix create memory region overlap check The current check is incorrect; it only checks if the beginning or end of a region is within an existing region. This doesn't account for userspace specifying a region that begins before and ends after an existing region. Change the logic to a range intersection check against gfns and uaddrs for each region. Remove mshv_partition_region_by_uaddr() as it is no longer used.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= 621191d709b14882270dfd8ea5d7d6cdfebe2c35 < 2183924dd834e0703f87e17c17e689bcbf55d69d2183924dd834e0703f87e17c17e689bcbf55d69d
linuxlinux>= 621191d709b14882270dfd8ea5d7d6cdfebe2c35 < ab3e7a78d83a61d335458cfe2e4d17eba69ae73dab3e7a78d83a61d335458cfe2e4d17eba69ae73d
linuxlinux>= 621191d709b14882270dfd8ea5d7d6cdfebe2c35 < ba9eb9b86d232854e983203dc2fb1ba18e316681ba9eb9b86d232854e983203dc2fb1ba18e316681
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.15.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.