
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68225 is a vulnerability in the Linux kernel's lib/test_kho module where KHO (Kexec Handover) commands may be issued without first verifying that KHO is enabled, resulting in access to uninitialized internal data structures. The flaw was published on December 16, 2025, and affects Linux kernel versions from commit b753522bed0b7e388a643f58d91bd81d8849ba43 up to (but not including) the patched commits. Fixed versions include Linux 6.17.10 and 6.18. No CVSS base score has been assigned at this time, and the EPSS score is approximately 0.018% (EUVD, Feedly).
The root cause is a missing precondition check in the lib/test_kho kernel test module: KHO commands are executed without first confirming that the KHO subsystem is enabled, meaning its internal data structures have not been initialized at the time of access. This constitutes a use-before-initialization or null-pointer dereference class of issue (broadly CWE-457: Use of Uninitialized Variable). The vulnerability is local in nature, requiring the ability to trigger the test module on a kernel where KHO support is compiled in but not enabled at runtime. Patches were applied to two stable branches, as referenced in the kernel git repository (EUVD).
Exploitation of this vulnerability could cause a kernel crash or undefined behavior due to access to uninitialized KHO data structures, resulting in a denial-of-service condition (system crash/panic). Because the affected code resides in a kernel test module (lib/test_kho), the practical impact is limited to systems where this test module is loaded and KHO is not enabled. There is no evidence of confidentiality or integrity impact beyond system availability (EUVD, Feedly).
There is no public proof-of-concept exploit code, no known in-the-wild exploitation, and no threat actor attribution associated with CVE-2025-68225. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term (Feedly).
The Linux kernel maintainers have released patches addressing this issue in versions 6.17.10 and 6.18. Users running affected kernel versions (from commit b753522bed0b7e388a643f58d91bd81d8849ba43) should upgrade to a patched release. Ubuntu has issued security notices USN-8094-1 through USN-8094-5 and USN-8152-1 addressing this and related kernel vulnerabilities (Ubuntu USN-8094-1, Ubuntu USN-8152-1). As a workaround, avoiding loading the test_kho kernel module on production systems mitigates exposure, since the vulnerable code is part of a test module not typically loaded in production environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."