CVE-2025-68191

UnknownEPSS 0.17%

Last modified

CVE-2025-68191 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: use netdev_warn() instead of netdev_WARN() netdev_WARN() uses WARN/WARN_ON to print a backtrace along with file and line information. In this case, udp_tunnel_nic_register() returning an error is just a failed operation, not a kernel bug. udp_tunnel_nic_register() can fail due to a memory allocation failure (kzalloc() or udp_tunnel_nic_alloc()). This is a normal runtime error and not a kernel bug. Replace netdev_WARN() with netdev_warn() accordingly.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: use netdev_warn() instead of netdev_WARN() netdev_WARN() uses WARN/WARN_ON to print a backtrace along with file and line information. In this case, udp_tunnel_nic_register() returning an error is just a failed operation, not a kernel bug. udp_tunnel_nic_register() can fail due to a memory allocation failure (kzalloc() or udp_tunnel_nic_alloc()). This is a normal runtime error and not a kernel bug. Replace netdev_WARN() with netdev_warn() accordingly.

Metrics

EPSS Probability
0.17%

6.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < 087f1ed450dc6e7e49ffbbbe5b78be1218c6d5e0; >= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < 45e4e4a8772fa1c5f6f38e82b732b3a9d8137af4; >= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < 7758ec35ff3e9a31558eda4f0f9eb0ddfa78a8ba; >= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < c018a87942bf1607aeebf8dba5a210ca9a09a0fd; >= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < 51b3033088f0420b19027e3d54cd989b6ebd987e; >= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < 3c3b148bf8384c8a787753cf20abde1c5731f97f; >= cc4e3835eff474aa274d6e1d18f69d9d296d3b76, < dc2f650f7e6857bf384069c1a56b2937a1ee370d
LinuxLinux5.9

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-68191?
In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: use netdev_warn() instead of netdev_WARN() netdev_WARN() uses WARN/WARN_ON to print a backtrace along with file and line information. In this case, udp_tunnel_nic_register() returning an error is just a failed operation, not a kernel bug. udp_tunnel_nic_register() can fail due to a memory allocation failure (kzalloc() or udp_tunnel_nic_alloc()). This is a normal runtime error and not a kernel bug. Replace netdev_WARN() with netdev_warn() accordingly.
How severe is CVE-2025-68191?
Severity scoring for CVE-2025-68191 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2025-68191?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-68191?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST