PT-2025-51601 · Linux+3 · Linux Kernel+3

Published

2025-08-29

·

Updated

2026-04-20

·

CVE-2025-68188

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue where the tcp fastopen active disable ofo check() function does not properly handle memory management, potentially leading to a Use-After-Free (UAF) condition on dst dev()->flags. The issue is addressed by utilizing Read-Copy-Update (RCU) to avoid a pair of atomic operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-72538
BDU:2026-01318
CVE-2025-68188
ECHO-68F0-9ABF-FF62
OESA-2026-1759
OESA-2026-1760
OESA-2026-1761
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu