cbcvebase.
CVE-2025-68744
published 2025-12-24

CVE-2025-68744: In the Linux kernel, the following vulnerability has been resolved: bpf: Free special fields when update [lru_,]percpu_hash maps As [lru_,]percpu_hash maps…

PriorityP419high7.2
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Free special fields when update [lru_,]percpu_hash maps As [lru_,]percpu_hash maps support BPF_KPTR_{REF,PERCPU}, missing calls to 'bpf_obj_free_fields()' in 'pcpu_copy_value()' could cause the memory referenced by BPF_KPTR_{REF,PERCPU} fields to be held until the map gets freed. Fix this by calling 'bpf_obj_free_fields()' after 'copy_map_value[,_long]()' in 'pcpu_copy_value()'.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a < 994d6303ed0b84cbc795bb5becf7ed6de40d3f3c994d6303ed0b84cbc795bb5becf7ed6de40d3f3c
linuxlinux>= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a < 3bf1378747e251571e0de15e7e0a6bf2919044e73bf1378747e251571e0de15e7e0a6bf2919044e7
linuxlinux>= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a < 96a5cb7072cabbac5c66ac9318242c3bdceebb6896a5cb7072cabbac5c66ac9318242c3bdceebb68
linuxlinux>= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a < 4a03d69cece145e4fb527464be29c3806aa3221e4a03d69cece145e4fb527464be29c3806aa3221e
linuxlinux>= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a < 6af6e49a76c9af7d42eb923703e7648cb2bf401a6af6e49a76c9af7d42eb923703e7648cb2bf401a
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.4.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-hwe-6.8

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_msrc5.5MEDIUM
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.