cbcvebase.
CVE-2025-68782
published 2026-01-13

CVE-2025-68782: In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd->t_task_cdb…

PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.50%
40.2th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd->t_task_cdb fails, it remains NULL but is later dereferenced in the 'err' path. In case of error, reset NULL t_task_cdb value to point at the default fixed-size buffer. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 6cac97b12bdab04832e0416d049efcd0d48d303b6cac97b12bdab04832e0416d049efcd0d48d303b
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 45fd86b444105c8bd07a763f58635c87e5dc7aea45fd86b444105c8bd07a763f58635c87e5dc7aea
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 8727663ded659aad55eef21e3864ebf5a4796a968727663ded659aad55eef21e3864ebf5a4796a96
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 0260ad551b0815eb788d47f32899fbcd65d6f1280260ad551b0815eb788d47f32899fbcd65d6f128
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 0d36db68fdb8a3325386fd9523b67735f944e1f30d36db68fdb8a3325386fd9523b67735f944e1f3
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 8edbb9e371af186b4cf40819dab65fafe109df4d8edbb9e371af186b4cf40819dab65fafe109df4d
linuxlinux>= 9e95fb805dc043cc8ed878a08d1583e4097a5f80 < 5053eab38a4c4543522d0c320c639c56a8b599085053eab38a4c4543522d0c320c639c56a8b59908
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 5.8.0 < 5.10.2485.10.248
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.