CVE-2025-68200

Source
https://cve.org/CVERecord?id=CVE-2025-68200
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68200.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68200
Downstream
Related
Published
2025-12-16T13:48:28.793Z
Modified
2026-03-23T05:07:13.233149971Z
Summary
bpf: Add bpf_prog_run_data_pointers()
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Add bpfprogrundatapointers()

syzbot found that clsbpfclassify() is able to change tcskbcb(skb)->dropreason triggering a warning in skskbreasondrop().

WARNING: CPU: 0 PID: 5965 at net/core/skbuff.c:1192 __skskbreasondrop net/core/skbuff.c:1189 [inline] WARNING: CPU: 0 PID: 5965 at net/core/skbuff.c:1192 skskbreasondrop+0x76/0x170 net/core/skbuff.c:1214

struct tcskbcb has been added in commit ec624fe740b4 ("net/sched: Extend qdisc control block with tc control block"), which added a wrong interaction with db58ba459202 ("bpf: wire in data and dataend for clsact_bpf").

drop_reason was added later.

Add bpfprogrundatapointers() helper to save/restore the netsched storage colliding with BPF datameta/data_end.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68200.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0d76daf2013ce1da20eab5e26bd81d983e1c18fb
Fixed
c4cdd143c35974a2cedd000fa9eb3accc3023b20
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec624fe740b416fb68d536b37fb8eef46f90b5c2
Fixed
5e149d8a8e732126fb6014efd60075cf63a73f91
Fixed
baa61dcaa50b7141048c8d2aede7fe9ed8f21d11
Fixed
6392e5f4b1a3cce10e828309baf35d22abd3457d
Fixed
8dd2fe5f5d586c8e87307b7a271f6b994afcc006
Fixed
4ef92743625818932b9c320152b58274c05e5053

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68200.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.197
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.159
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.59
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.17.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68200.json"