CVE-2025-68724
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68724 is an integer overflow vulnerability in the Linux kernel's asymmetric_keys cryptography module, specifically in the asymmetric_key_generate_id function. The flaw allows a locally authenticated, low-privileged attacker to trigger a buffer overflow by supplying a specially crafted X.509 certificate with oversized fields (e.g., ASN.1 INTEGER serial numbers or issuer names). It was published on December 24, 2025, with a patch released on December 25, 2025. Affected products include Azure Linux 3 (AZL3) kernel versions 6.6.117.1-1 and 6.6.119.3-3, as well as upstream Linux kernel versions prior to the stable fixes. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).

Technical details

The root cause is a missing integer overflow check (CWE-190: Integer Overflow or Wraparound) in asymmetric_key_generate_id() when summing binary blob lengths and the size of an asymmetric_key_id structure. Without validation, an attacker can supply X.509 certificate fields — such as ASN.1 INTEGER serial numbers or issuer names — that are arbitrarily large, causing the computed allocation size to wrap around and result in an undersized heap buffer. Subsequent data copying into this buffer constitutes a heap-based buffer overflow. The fix introduces check_add_overflow() to detect the overflow condition and return ERR_PTR(-EOVERFLOW) before any allocation occurs. Exploitation requires local access with at least low privileges, as the attacker must be able to present a malicious certificate to the kernel's asymmetric key subsystem (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in a kernel-level buffer overflow that can cause a Denial of Service (DoS) by crashing the kernel or inducing system instability (kernel panic). The CVSS scoring reflects high availability impact with no confidentiality or integrity impact, meaning the primary risk is system unavailability rather than data exfiltration or unauthorized modification. Affected systems include Azure Linux 3 instances and any Linux distribution running unpatched kernel versions prior to the stable fixes, with the scope limited to the local system (Microsoft MSRC, Feedly).

Mitigation and workarounds

Apply the available kernel patches immediately. Upstream Linux kernel fixes are available in stable versions 6.19-rc1, 6.18.2, 6.17.13, and 6.12.63, as well as in backported commits for earlier series. For Azure Linux 3, update beyond the vulnerable kernel versions 6.6.117.1-1 and 6.6.119.3-3. Downstream distributions including Debian (linux 6.1.162-1), Ubuntu (USN-8179-x, USN-8184-1, USN-8185-x, USN-8203-1, USN-8258-1, USN-8260-1, USN-8265-1), Red Hat (RHSA-2026:13577, RHSA-2026:13578, RHSA-2026:19569, RHSA-2026:21556, RHSA-2026:23237), AlmaLinux, Rocky Linux, and Amazon Linux 2 have all released patches. Where immediate patching is not possible, restrict local system access to trusted users only and monitor for unexpected kernel panics (Microsoft MSRC, Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management