PT-2025-51647 · Linux+2 · Linux Kernel+2

CVE-2025-68234

·

Published

2025-11-20

·

Updated

2026-04-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue within the io uring/cmd net subsystem related to incorrect argument types used in the skb queue splice() function. Specifically, when timestamp retrieval requires retries and a local list of SKB (Socket Buffer) structures already contains entries, the arguments passed to the skb queue splice() helper function are transposed. This results in an incorrect direction of splicing into the on-stack list. The issue affects the handling of socket queue operations during timestamp retrieval retries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10430
CVE-2025-68234
SUSE-SU-2026:1078-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu