CVE-2025-68353
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68353 is a NULL pointer dereference vulnerability in the Linux kernel's VXLAN network implementation, specifically in the vxlan_xmit_one function. The flaw was introduced in Linux kernel v6.7 when code path changes in vxlan_xmit_one inadvertently removed socket pointer validity checks (sock4/sock6) that previously existed in vxlan(6)_get_route. It affects Linux kernel versions starting from v6.7 up to the patched commits, with fixes available in kernel 6.18.2 and 6.19-rc1. The vulnerability was publicly disclosed on December 24, 2025, and carries a CVSS v3.1 base score of 7.0 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is a NULL pointer dereference (CWE-476) in the vxlan_xmit_one function of the Linux kernel's VXLAN driver (net/vxlan). When a VXLAN network interface is brought down, the sock4 or sock6 socket pointers can be NULL; prior to v6.7, validity checks in vxlan(6)_get_route prevented dereferencing these pointers, but commits introduced in v6.7 altered the code path and inadvertently dropped those checks. An attacker with low-privilege local access can trigger this condition — for example, by manipulating network interface state — causing a kernel NULL pointer dereference at address 0x0000000000000010, resulting in a kernel oops/panic. The fix restores the missing NULL checks and was bundled into a single commit covering both affected code paths (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful exploitation causes a kernel NULL pointer dereference, leading to a kernel panic (system crash) and denial of service. The CVSS v3.1 scoring reflects high impacts to confidentiality, integrity, and availability, though in practice the primary observable impact is system instability and potential kernel memory corruption. Systems running VXLAN-based overlay networks — common in cloud, container, and virtualized environments — are at elevated risk of service disruption if a local low-privileged user can manipulate interface state (Red Hat Advisory, Red Hat Bugzilla).

Mitigation and workarounds

The primary remediation is to update the Linux kernel to a patched version: the fix is included in kernel 6.18.2 and 6.19-rc1, with stable patches at commits 4ac26aafdc8c and 1f73a56f9860. Ubuntu has issued security notices USN-8177-1, USN-8177-2, USN-8183-1, USN-8183-2, USN-8245-1, and USN-8257-1 addressing this vulnerability. As a temporary workaround, administrators should avoid unnecessarily bringing down VXLAN interfaces and restrict local user access on systems running VXLAN-based networking (Red Hat Advisory, Ubuntu USN-8177-1, Ubuntu USN-8183-1).

Community reactions

Red Hat triaged the vulnerability as medium severity and opened a public Bugzilla entry shortly after disclosure on December 24, 2025. Ubuntu issued multiple security notices (USN-8177-1/2, USN-8183-1/2, USN-8245-1, USN-8257-1) addressing the flaw across various kernel flavors. No notable independent researcher commentary or significant social media discussion has been observed beyond standard vendor advisory channels (Red Hat Bugzilla, Ubuntu USN-8177-1).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management