CVE-2025-68353

Source
https://cve.org/CVERecord?id=CVE-2025-68353
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68353.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68353
Downstream
Related
Published
2025-12-24T10:32:44.068Z
Modified
2026-04-02T13:03:35.576428Z
Summary
net: vxlan: prevent NULL deref in vxlan_xmit_one
Details

In the Linux kernel, the following vulnerability has been resolved:

net: vxlan: prevent NULL deref in vxlanxmitone

Neither sock4 nor sock6 pointers are guaranteed to be non-NULL in vxlanxmitone, e.g. if the iface is brought down. This can lead to the following NULL dereference:

BUG: kernel NULL pointer dereference, address: 0000000000000010 Oops: Oops: 0000 [#1] SMP NOPTI RIP: 0010:vxlanxmitone+0xbb3/0x1580 Call Trace: vxlanxmit+0x429/0x610 devhardstartxmit+0x55/0xa0 _devqueuexmit+0x6d0/0x7f0 ipfinishoutput2+0x24b/0x590 ipoutput+0x63/0x110

Mentioned commits changed the code path in vxlanxmitone and as a side effect the sock4/6 pointer validity checks in vxlan(6)getroute were lost. Fix this by adding back checks.

Since both commits being fixed were released in the same version (v6.7) and are strongly related, bundle the fixes in a single commit.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68353.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6f19b2c136d98a84d79030b53e23d405edfdc783
Fixed
4ac26aafdc8c7271414e2e7c0b2cb266a26591bc
Fixed
1f73a56f986005f0bc64ed23873930e2ee4f5911

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68353.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68353.json"