cbcvebase.
CVE-2025-68799
published 2026-01-13

CVE-2025-68799: In the Linux kernel, the following vulnerability has been resolved: caif: fix integer underflow in cffrml_receive() The cffrml_receive() function extracts a…

PriorityP342high8.1CVSS 3.1
AVAACLPRNUINSUCHINAH
EPSS
0.27%
19.4th percentile
In the Linux kernel, the following vulnerability has been resolved: caif: fix integer underflow in cffrml_receive() The cffrml_receive() function extracts a length field from the packet header and, when FCS is disabled, subtracts 2 from this length without validating that len >= 2. If an attacker sends a malicious packet with a length field of 0 or 1 to an interface with FCS disabled, the subtraction causes an integer underflow. This can lead to memory exhaustion and kernel instability, potential information disclosure if padding contains uninitialized kernel memory. Fix this by validating that len >= 2 before performing the subtraction.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < f407f1c9f45bbf5c99fd80b3f3f4a94fdbe35691f407f1c9f45bbf5c99fd80b3f3f4a94fdbe35691
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < c54091eec6fed19e94182aa05dd6846600a642f7c54091eec6fed19e94182aa05dd6846600a642f7
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < 785c7be6361630070790f6235b696da156ac71b3785c7be6361630070790f6235b696da156ac71b3
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < f818cd472565f8b0c2c409b040e0121c5cf8592cf818cd472565f8b0c2c409b040e0121c5cf8592c
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < 4ec29714aa4e0601ea29d2f02b461fc0ac92c2c34ec29714aa4e0601ea29d2f02b461fc0ac92c2c3
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < 21fdcc00656a60af3c7aae2dea8dd96abd35519c21fdcc00656a60af3c7aae2dea8dd96abd35519c
linuxlinux>= b482cd2053e3b90a7b33a78c63cdb6badf2ec383 < 8a11ff0948b5ad09b71896b7ccc850625f9878d18a11ff0948b5ad09b71896b7ccc850625f9878d1
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.35 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.