CVE-2025-68363
Last modified
CVE-2025-68363 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: bpf: Check skb->transport_header is set in bpf_skb_check_mtu The bpf_skb_check_mtu helper needs to use skb->transport_header when the BPF_MTU_CHK_SEGS flag is used: bpf_skb_check_mtu(skb, ifindex, &mtu_len, 0, BPF_MTU_CHK_SEGS) The transport_header is not always set. There is a WARN_ON_ONCE report when CONFIG_DEBUG_NET is enabled + skb->gso_size is set + bpf_prog_test_run is used: WARNING: CPU: 1 PID: 2216 at ./include/linux/skbuff.h:3071 skb_gso_validate_network_len bpf_skb_check_mtu bpf_prog_3920e25740a41171_tc_chk_segs_flag # A test in the next patch bpf_test_run bpf_prog_test_run_skb For a normal ingress skb (not test_run), skb_reset_transport_header is performed but there is plan to avoid setting it as described in commit 2170a1f09148 ("net: no longer reset transport_header in __netif_receive_skb_core()"). This patch fixes the bpf helper by checking skb_transport_header_was_set(). EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Check skb->transport_header is set in bpf_skb_check_mtu The bpf_skb_check_mtu helper needs to use skb->transport_header when the BPF_MTU_CHK_SEGS flag is used: bpf_skb_check_mtu(skb, ifindex, &mtu_len, 0, BPF_MTU_CHK_SEGS) The transport_header is not always set. There is a WARN_ON_ONCE report when CONFIG_DEBUG_NET is enabled + skb->gso_size is set + bpf_prog_test_run is used: WARNING: CPU: 1 PID: 2216 at ./include/linux/skbuff.h:3071 skb_gso_validate_network_len bpf_skb_check_mtu bpf_prog_3920e25740a41171_tc_chk_segs_flag # A test in the next patch bpf_test_run bpf_prog_test_run_skb For a normal ingress skb (not test_run), skb_reset_transport_header is performed but there is plan to avoid setting it as described in commit 2170a1f09148 ("net: no longer reset transport_header in __netif_receive_skb_core()"). This patch fixes the bpf helper by checking skb_transport_header_was_set(). The check is done just before skb->transport_header is used, to avoid breaking the existing bpf prog. The WARN_ON_ONCE is limited to bpf_prog_test_run, so targeting bpf-next.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 34b2021cc61642d61c3cf943d9e71925b827941b, < b3171a5e4622e915e94599a55f4964078bdec27e; >= 34b2021cc61642d61c3cf943d9e71925b827941b, < 97b876fa88322625228792cf7a5fd77531815a80; >= 34b2021cc61642d61c3cf943d9e71925b827941b, < 30ce906557a21adef4cba5901c8e995dc18263a9; >= 34b2021cc61642d61c3cf943d9e71925b827941b, < 1c30e4afc5507f0069cc09bd561e510e4d97fbf7; >= 34b2021cc61642d61c3cf943d9e71925b827941b, < 942268e2726ac7f16e3ec49dbfbbbe7cf5af9da5; >= 34b2021cc61642d61c3cf943d9e71925b827941b, < d946f3c98328171fa50ddb908593cf833587f725 |
| Linux | Linux | 5.12 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68363?
How severe is CVE-2025-68363?
How do I fix CVE-2025-68363?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68358In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-68359In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-6836A vulnerability classified as critical has been found in cod…9.8
- CVE-2025-68360In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2025-68361In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68362In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68364In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68365In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-68366In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68367In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68368In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68369In the Linux kernel, the following vulnerability has been re…7.5
Are you affected by CVE-2025-68363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
