CVE-2025-68173
Last modified
CVE-2025-68173 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix softlockup in ftrace_module_enable A soft lockup was observed when loading amdgpu module. If a module has a lot of tracable functions, multiple calls to kallsyms_lookup can spend too much time in RCU critical section and with disabled preemption, causing kernel panic. This is the same issue that was fixed in commit d0b24b4e91fc ("ftrace: Prevent RCU stall on PREEMPT_VOLUNTARY kernels") and commit 42ea22e754ba ("ftrace: Add cond_resched() to ftrace_graph_set_hash()"). Fix it the same way by adding cond_resched() in ftrace_module_enable.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix softlockup in ftrace_module_enable A soft lockup was observed when loading amdgpu module. If a module has a lot of tracable functions, multiple calls to kallsyms_lookup can spend too much time in RCU critical section and with disabled preemption, causing kernel panic. This is the same issue that was fixed in commit d0b24b4e91fc ("ftrace: Prevent RCU stall on PREEMPT_VOLUNTARY kernels") and commit 42ea22e754ba ("ftrace: Add cond_resched() to ftrace_graph_set_hash()"). Fix it the same way by adding cond_resched() in ftrace_module_enable.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b7ffffbb46f205e7727a18bcc7a46c3c2b534f7c, < a1dd0abd741a8111260676da729825d6c1461a71; >= b7ffffbb46f205e7727a18bcc7a46c3c2b534f7c, < e81e6d6d99b16dae11adbeda5c996317942a940c; >= b7ffffbb46f205e7727a18bcc7a46c3c2b534f7c, < 40c8ee40e48a2c82c762539952ed8fc0571db5bf; >= b7ffffbb46f205e7727a18bcc7a46c3c2b534f7c, < 7e3c96010ade29bb340a5bdce8675f50c7f59001; >= b7ffffbb46f205e7727a18bcc7a46c3c2b534f7c, < 4099b98203d6b33d990586542fa5beee408032a3 |
| Linux | Linux | 4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68173?
How severe is CVE-2025-68173?
How do I fix CVE-2025-68173?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68168In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68169In the Linux kernel, the following vulnerability has been re…
- CVE-2025-6817A vulnerability, which was classified as problematic, has be…3.3
- CVE-2025-68170In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68171In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68172In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68174In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68175In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68176In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68177In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68178In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68179In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2025-68173?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
