CVE-2025-68763 — Linux vulnerability
24 documents8 sources
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 92.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 5
Latest updateApr 17
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: starfive - Correctly handle return of sg_nents_for_len
The return value of sg_nents_for_len was assigned to an unsigned long
in starfive_hash_digest, causing negative error codes to be converted
to large positive integers.
Add error checking for sg_nents_for_len and return immediately on
failure to prevent potential buffer overflows.
Affected Packages12 packages
▶CVEListV5linux/linux7883d1b28a2b0e62edcacea22de6b36a1918b15a — 6cd14414394b4f3d6e1ed64b8241d1fcc2271820+5