CVE-2025-68225
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-68225 is a vulnerability in the Linux kernel's lib/test_kho module where KHO (Kexec Handover) commands may be issued without first verifying that KHO is enabled, resulting in access to uninitialized internal data structures. The flaw was published on December 16, 2025, and affects Linux kernel versions from commit b753522bed0b7e388a643f58d91bd81d8849ba43 up to (but not including) the patched commits. Fixed versions include Linux 6.17.10 and 6.18. No CVSS base score has been assigned at this time, and the EPSS score is approximately 0.018% (EUVD, Feedly).

Technical details

The root cause is a missing precondition check in the lib/test_kho kernel test module: KHO commands are executed without first confirming that the KHO subsystem is enabled, meaning its internal data structures have not been initialized at the time of access. This constitutes a use-before-initialization or null-pointer dereference class of issue (broadly CWE-457: Use of Uninitialized Variable). The vulnerability is local in nature, requiring the ability to trigger the test module on a kernel where KHO support is compiled in but not enabled at runtime. Patches were applied to two stable branches, as referenced in the kernel git repository (EUVD).

Impact

Exploitation of this vulnerability could cause a kernel crash or undefined behavior due to access to uninitialized KHO data structures, resulting in a denial-of-service condition (system crash/panic). Because the affected code resides in a kernel test module (lib/test_kho), the practical impact is limited to systems where this test module is loaded and KHO is not enabled. There is no evidence of confidentiality or integrity impact beyond system availability (EUVD, Feedly).

Exploitability

There is no public proof-of-concept exploit code, no known in-the-wild exploitation, and no threat actor attribution associated with CVE-2025-68225. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this issue in versions 6.17.10 and 6.18. Users running affected kernel versions (from commit b753522bed0b7e388a643f58d91bd81d8849ba43) should upgrade to a patched release. Ubuntu has issued security notices USN-8094-1 through USN-8094-5 and USN-8152-1 addressing this and related kernel vulnerabilities (Ubuntu USN-8094-1, Ubuntu USN-8152-1). As a workaround, avoiding loading the test_kho kernel module on production systems mitigates exposure, since the vulnerable code is part of a test module not typically loaded in production environments.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management