CVE-2025-68341
A race condition vulnerability exists in the Linux kernel's veth component. This flaw occurs when multiple processes attempt to use the same BPF network context simultaneously, potentially leading to unexpected behavior.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel where the veth component is used, specifically in environments where threaded-NAPI mode is active.
Real-world impact
An attacker could potentially exploit this race condition to cause system instability or unexpected behavior within the network subsystem.
Why this severity
The critical score reflects that this is a network-accessible vulnerability that can be exploited without user interaction or special privileges, potentially impacting the confidentiality, integrity, and availability of the system.
What to do about it
- 01Apply the fix provided in the Linux kernel commit fa349e396e48.
- 02Apply the fix provided in the Linux kernel commit 401cb7dae813.
NVD-referenced vendor advisory
Timeline
- Dec 23, 2025 · Dec 23, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.