PT-2025-51629 · Linux · Linux Kernel

CVE-2025-68216

·

Published

2025-11-20

·

Updated

2025-12-19

CVSS v2.0

1.4

Low

VectorAV:A/AC:H/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The LoongArch BPF trampoline implementation is incompatible with tracing functions in kernel modules, leading to issues such as test failures, kernel lockups when attaching BPF programs to module functions, and traffic disruption in critical modules like WireGuard when using fentry tracing. The issue arises from problems in the trampoline code for handling kernel module functions. Disabling trampoline attachments to kernel module functions on LoongArch serves as a temporary mitigation. The bpf selftests/module attach test consistently fails, and the handle fentry program fails to attach.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Privilege Assignment

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10697
CVE-2025-68216

Affected Products

Linux Kernel