CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-68284

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable

Description

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() The len field originates from untrusted network packets. Boundary checks have been added to prevent potential out-of-bounds writes when decrypting the connection secret or processing service tickets. [ idryomov: changelog ]

Affected packages

Linux Kernel 5.11.0 → 5.15.197
Linux Kernel 5.16.0 → 6.1.159
Linux Kernel 6.13.0 → 6.17.11
Linux Kernel 6.2.0 → 6.6.119
Linux Kernel 6.7.0 → 6.12.61

References

Status: profiled · ingested 2026-07-30T12:00:00.000Z