CVE-2025-68744
Last modified
CVE-2025-68744 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: bpf: Free special fields when update [lru_,]percpu_hash maps As [lru_,]percpu_hash maps support BPF_KPTR_{REF,PERCPU}, missing calls to 'bpf_obj_free_fields()' in 'pcpu_copy_value()' could cause the memory referenced by BPF_KPTR_{REF,PERCPU} fields to be held until the map gets freed. Fix this by calling 'bpf_obj_free_fields()' after 'copy_map_value[,_long]()' in 'pcpu_copy_value()'.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Free special fields when update [lru_,]percpu_hash maps As [lru_,]percpu_hash maps support BPF_KPTR_{REF,PERCPU}, missing calls to 'bpf_obj_free_fields()' in 'pcpu_copy_value()' could cause the memory referenced by BPF_KPTR_{REF,PERCPU} fields to be held until the map gets freed. Fix this by calling 'bpf_obj_free_fields()' after 'copy_map_value[,_long]()' in 'pcpu_copy_value()'.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a, < 994d6303ed0b84cbc795bb5becf7ed6de40d3f3c; >= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a, < 3bf1378747e251571e0de15e7e0a6bf2919044e7; >= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a, < 96a5cb7072cabbac5c66ac9318242c3bdceebb68; >= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a, < 4a03d69cece145e4fb527464be29c3806aa3221e; >= 65334e64a493c6a0976de7ad56bf8b7a9ff04b4a, < 6af6e49a76c9af7d42eb923703e7648cb2bf401a |
| Linux | Linux | 6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68744?
How severe is CVE-2025-68744?
How do I fix CVE-2025-68744?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68739In the Linux kernel, the following vulnerability has been re…
- CVE-2025-6874A vulnerability, which was classified as critical, was found…8.8
- CVE-2025-68740In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68741In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-68742In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68743In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68745In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-68746In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68747In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68748In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68749In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2025-6875A vulnerability has been found in SourceCodester Best Salon …8.8
Are you affected by CVE-2025-68744?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
