cbcvebase.
CVE-2025-68763
published 2026-01-05

CVE-2025-68763: In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Correctly handle return of sg_nents_for_len The return value of…

PriorityP418high7.2
EPSS
0.18%
7.8th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Correctly handle return of sg_nents_for_len The return value of sg_nents_for_len was assigned to an unsigned long in starfive_hash_digest, causing negative error codes to be converted to large positive integers. Add error checking for sg_nents_for_len and return immediately on failure to prevent potential buffer overflows.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= 7883d1b28a2b0e62edcacea22de6b36a1918b15a < 6cd14414394b4f3d6e1ed64b8241d1fcc22718206cd14414394b4f3d6e1ed64b8241d1fcc2271820
linuxlinux>= 7883d1b28a2b0e62edcacea22de6b36a1918b15a < 0c3854d65cc4402cb8c52d4d773450a06efecab60c3854d65cc4402cb8c52d4d773450a06efecab6
linuxlinux>= 7883d1b28a2b0e62edcacea22de6b36a1918b15a < 1af5c973dd744e29fa22121f43e8646b7a7a71a71af5c973dd744e29fa22121f43e8646b7a7a71a7
linuxlinux>= 7883d1b28a2b0e62edcacea22de6b36a1918b15a < 9b3f71cf02e04cfaa482155e3078707fe7f8aef49b3f71cf02e04cfaa482155e3078707fe7f8aef4
linuxlinux>= 7883d1b28a2b0e62edcacea22de6b36a1918b15a < e9eb52037a529fbb307c290e9951a62dd728b03de9eb52037a529fbb307c290e9951a62dd728b03d
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.5.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-hwe-6.8
ubuntulinux-ibm-6.8
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.