CVE-2025-68785 (GCVE-0-2025-68785)
Vulnerability from cvelistv5
Published
2026-01-13 15:28
Modified
2026-08-05 12:11
Summary
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix middle attribute validation in push_nsh() action The push_nsh() action structure looks like this: OVS_ACTION_ATTR_PUSH_NSH(OVS_KEY_ATTR_NSH(OVS_NSH_KEY_ATTR_BASE,...)) The outermost OVS_ACTION_ATTR_PUSH_NSH attribute is OK'ed by the nla_for_each_nested() inside __ovs_nla_copy_actions(). The innermost OVS_NSH_KEY_ATTR_BASE/MD1/MD2 are OK'ed by the nla_for_each_nested() inside nsh_key_put_from_nlattr(). But nothing checks if the attribute in the middle is OK. We don't even check that this attribute is the OVS_KEY_ATTR_NSH. We just do a double unwrap with a pair of nla_data() calls - first time directly while calling validate_push_nsh() and the second time as part of the nla_for_each_nested() macro, which isn't safe, potentially causing invalid memory access if the size of this attribute is incorrect. The failure may not be noticed during validation due to larger netlink buffer, but cause trouble later during action execution where the buffer is allocated exactly to the size: BUG: KASAN: slab-out-of-bounds in nsh_hdr_from_nlattr+0x1dd/0x6a0 [openvswitch] Read of size 184 at addr ffff88816459a634 by task a.out/22624 CPU: 8 UID: 0 PID: 22624 6.18.0-rc7+ #115 PREEMPT(voluntary) Call Trace: <TASK> dump_stack_lvl+0x51/0x70 print_address_description.constprop.0+0x2c/0x390 kasan_report+0xdd/0x110 kasan_check_range+0x35/0x1b0 __asan_memcpy+0x20/0x60 nsh_hdr_from_nlattr+0x1dd/0x6a0 [openvswitch] push_nsh+0x82/0x120 [openvswitch] do_execute_actions+0x1405/0x2840 [openvswitch] ovs_execute_actions+0xd5/0x3b0 [openvswitch] ovs_packet_cmd_execute+0x949/0xdb0 [openvswitch] genl_family_rcv_msg_doit+0x1d6/0x2b0 genl_family_rcv_msg+0x336/0x580 genl_rcv_msg+0x9f/0x130 netlink_rcv_skb+0x11f/0x370 genl_rcv+0x24/0x40 netlink_unicast+0x73e/0xaa0 netlink_sendmsg+0x744/0xbf0 __sys_sendto+0x3d6/0x450 do_syscall_64+0x79/0x2c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> Let's add some checks that the attribute is properly sized and it's the only one attribute inside the action. Technically, there is no real reason for OVS_KEY_ATTR_NSH to be there, as we know that we're pushing an NSH header already, it just creates extra nesting, but that's how uAPI works today. So, keeping as it is.
Impacted products
Vendor Product Version
Linux Linux Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Version: b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-68785",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-16T19:21:59.526641Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-16T19:22:11.052Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/openvswitch/flow_netlink.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d0c135b8bbbcf92836068fd395bebeb7ae6c7bef",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            },
            {
              "lessThan": "3bc2efff20a38b2c7ca18317649715df0dd62ced",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            },
            {
              "lessThan": "1b569db9c2f28b599e40050524aae5f7332bc294",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            },
            {
              "lessThan": "10ffc558246f2c75619aedda0921906095e46702",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            },
            {
              "lessThan": "2ecfc4433acdb149eafd7fb22d7fd4adf90b25e9",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            },
            {
              "lessThan": "c999153bfb2d1d9b295b7010d920f2a7c6d7595f",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            },
            {
              "lessThan": "5ace7ef87f059d68b5f50837ef3e8a1a4870c36e",
              "status": "affected",
              "version": "b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/openvswitch/flow_netlink.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "lessThan": "4.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.248",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.198",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.160",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.120",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.64",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.19",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.248",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.198",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.160",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.120",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.64",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.3",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix middle attribute validation in push_nsh() action\n\nThe push_nsh() action structure looks like this:\n\n OVS_ACTION_ATTR_PUSH_NSH(OVS_KEY_ATTR_NSH(OVS_NSH_KEY_ATTR_BASE,...))\n\nThe outermost OVS_ACTION_ATTR_PUSH_NSH attribute is OK\u0027ed by the\nnla_for_each_nested() inside __ovs_nla_copy_actions().  The innermost\nOVS_NSH_KEY_ATTR_BASE/MD1/MD2 are OK\u0027ed by the nla_for_each_nested()\ninside nsh_key_put_from_nlattr().  But nothing checks if the attribute\nin the middle is OK.  We don\u0027t even check that this attribute is the\nOVS_KEY_ATTR_NSH.  We just do a double unwrap with a pair of nla_data()\ncalls - first time directly while calling validate_push_nsh() and the\nsecond time as part of the nla_for_each_nested() macro, which isn\u0027t\nsafe, potentially causing invalid memory access if the size of this\nattribute is incorrect.  The failure may not be noticed during\nvalidation due to larger netlink buffer, but cause trouble later during\naction execution where the buffer is allocated exactly to the size:\n\n BUG: KASAN: slab-out-of-bounds in nsh_hdr_from_nlattr+0x1dd/0x6a0 [openvswitch]\n Read of size 184 at addr ffff88816459a634 by task a.out/22624\n\n CPU: 8 UID: 0 PID: 22624 6.18.0-rc7+ #115 PREEMPT(voluntary)\n Call Trace:\n  \u003cTASK\u003e\n  dump_stack_lvl+0x51/0x70\n  print_address_description.constprop.0+0x2c/0x390\n  kasan_report+0xdd/0x110\n  kasan_check_range+0x35/0x1b0\n  __asan_memcpy+0x20/0x60\n  nsh_hdr_from_nlattr+0x1dd/0x6a0 [openvswitch]\n  push_nsh+0x82/0x120 [openvswitch]\n  do_execute_actions+0x1405/0x2840 [openvswitch]\n  ovs_execute_actions+0xd5/0x3b0 [openvswitch]\n  ovs_packet_cmd_execute+0x949/0xdb0 [openvswitch]\n  genl_family_rcv_msg_doit+0x1d6/0x2b0\n  genl_family_rcv_msg+0x336/0x580\n  genl_rcv_msg+0x9f/0x130\n  netlink_rcv_skb+0x11f/0x370\n  genl_rcv+0x24/0x40\n  netlink_unicast+0x73e/0xaa0\n  netlink_sendmsg+0x744/0xbf0\n  __sys_sendto+0x3d6/0x450\n  do_syscall_64+0x79/0x2c0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  \u003c/TASK\u003e\n\nLet\u0027s add some checks that the attribute is properly sized and it\u0027s\nthe only one attribute inside the action.  Technically, there is no\nreal reason for OVS_KEY_ATTR_NSH to be there, as we know that we\u0027re\npushing an NSH header already, it just creates extra nesting, but\nthat\u0027s how uAPI works today.  So, keeping as it is."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The malformed PUSH_NSH action must be supplied through a local Open vSwitch Generic Netlink packet-execute or flow-management command. Network packets can trigger an installed action but cannot create the malformed action themselves.\nAC:L - A crafted attribute deterministically bypasses the missing middle-layer validation; no race or condition outside the attacker\u0027s control is required.\nPR:L - The commands require CAP_NET_ADMIN via GENL_UNS_ADMIN_PERM, but OVS is network-namespace-aware and this capability can be obtained by an unprivileged user through a new user and network namespace on permissive systems.\nUI:N - After obtaining local access, the attacker can create a datapath and submit the malicious Netlink command without any victim action.\nS:U - The vulnerable processing and resulting kernel impact remain within the Linux kernel\u0027s security authority; a user-namespace-to-kernel impact is treated as unchanged scope.\nC:H - The flaw causes a confirmed slab out-of-bounds read of 184 bytes, and the NSH metadata path permits reads up to 248 bytes beyond the copied action buffer, potentially exposing sensitive kernel heap contents.\nI:N - The invalid data is only read into a bounded 256-byte stack buffer and then into allocated packet headroom. No out-of-bounds kernel write, object corruption, or control-flow modification primitive is present.\nA:H - The malformed action can synchronously cause an invalid slab access during packet execution, leading to a kernel oops or panic, and the attacker can invoke it repeatedly."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:11:27.492Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d0c135b8bbbcf92836068fd395bebeb7ae6c7bef"
        },
        {
          "url": "https://git.kernel.org/stable/c/3bc2efff20a38b2c7ca18317649715df0dd62ced"
        },
        {
          "url": "https://git.kernel.org/stable/c/1b569db9c2f28b599e40050524aae5f7332bc294"
        },
        {
          "url": "https://git.kernel.org/stable/c/10ffc558246f2c75619aedda0921906095e46702"
        },
        {
          "url": "https://git.kernel.org/stable/c/2ecfc4433acdb149eafd7fb22d7fd4adf90b25e9"
        },
        {
          "url": "https://git.kernel.org/stable/c/c999153bfb2d1d9b295b7010d920f2a7c6d7595f"
        },
        {
          "url": "https://git.kernel.org/stable/c/5ace7ef87f059d68b5f50837ef3e8a1a4870c36e"
        }
      ],
      "title": "net: openvswitch: fix middle attribute validation in push_nsh() action",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-68785",
    "datePublished": "2026-01-13T15:28:58.930Z",
    "dateReserved": "2025-12-24T10:30:51.036Z",
    "dateUpdated": "2026-08-05T12:11:27.492Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-68785\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-06-16T19:21:59.526641Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-06-16T19:22:05.802Z\"}}], \"cna\": {\"title\": \"net: openvswitch: fix middle attribute validation in push_nsh() action\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"d0c135b8bbbcf92836068fd395bebeb7ae6c7bef\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"3bc2efff20a38b2c7ca18317649715df0dd62ced\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"1b569db9c2f28b599e40050524aae5f7332bc294\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"10ffc558246f2c75619aedda0921906095e46702\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"2ecfc4433acdb149eafd7fb22d7fd4adf90b25e9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"c999153bfb2d1d9b295b7010d920f2a7c6d7595f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b2d0f5d5dc53532e6f07bc546a476a55ebdfe0f3\", \"lessThan\": \"5ace7ef87f059d68b5f50837ef3e8a1a4870c36e\", \"versionType\": \"git\"}], \"programFiles\": [\"net/openvswitch/flow_netlink.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.15\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.15\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.248\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.198\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.160\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.120\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.64\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.18.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.18.*\"}, {\"status\": \"unaffected\", \"version\": \"6.19\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/openvswitch/flow_netlink.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d0c135b8bbbcf92836068fd395bebeb7ae6c7bef\"}, {\"url\": \"https://git.kernel.org/stable/c/3bc2efff20a38b2c7ca18317649715df0dd62ced\"}, {\"url\": \"https://git.kernel.org/stable/c/1b569db9c2f28b599e40050524aae5f7332bc294\"}, {\"url\": \"https://git.kernel.org/stable/c/10ffc558246f2c75619aedda0921906095e46702\"}, {\"url\": \"https://git.kernel.org/stable/c/2ecfc4433acdb149eafd7fb22d7fd4adf90b25e9\"}, {\"url\": \"https://git.kernel.org/stable/c/c999153bfb2d1d9b295b7010d920f2a7c6d7595f\"}, {\"url\": \"https://git.kernel.org/stable/c/5ace7ef87f059d68b5f50837ef3e8a1a4870c36e\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet: openvswitch: fix middle attribute validation in push_nsh() action\\n\\nThe push_nsh() action structure looks like this:\\n\\n OVS_ACTION_ATTR_PUSH_NSH(OVS_KEY_ATTR_NSH(OVS_NSH_KEY_ATTR_BASE,...))\\n\\nThe outermost OVS_ACTION_ATTR_PUSH_NSH attribute is OK\u0027ed by the\\nnla_for_each_nested() inside __ovs_nla_copy_actions().  The innermost\\nOVS_NSH_KEY_ATTR_BASE/MD1/MD2 are OK\u0027ed by the nla_for_each_nested()\\ninside nsh_key_put_from_nlattr().  But nothing checks if the attribute\\nin the middle is OK.  We don\u0027t even check that this attribute is the\\nOVS_KEY_ATTR_NSH.  We just do a double unwrap with a pair of nla_data()\\ncalls - first time directly while calling validate_push_nsh() and the\\nsecond time as part of the nla_for_each_nested() macro, which isn\u0027t\\nsafe, potentially causing invalid memory access if the size of this\\nattribute is incorrect.  The failure may not be noticed during\\nvalidation due to larger netlink buffer, but cause trouble later during\\naction execution where the buffer is allocated exactly to the size:\\n\\n BUG: KASAN: slab-out-of-bounds in nsh_hdr_from_nlattr+0x1dd/0x6a0 [openvswitch]\\n Read of size 184 at addr ffff88816459a634 by task a.out/22624\\n\\n CPU: 8 UID: 0 PID: 22624 6.18.0-rc7+ #115 PREEMPT(voluntary)\\n Call Trace:\\n  \u003cTASK\u003e\\n  dump_stack_lvl+0x51/0x70\\n  print_address_description.constprop.0+0x2c/0x390\\n  kasan_report+0xdd/0x110\\n  kasan_check_range+0x35/0x1b0\\n  __asan_memcpy+0x20/0x60\\n  nsh_hdr_from_nlattr+0x1dd/0x6a0 [openvswitch]\\n  push_nsh+0x82/0x120 [openvswitch]\\n  do_execute_actions+0x1405/0x2840 [openvswitch]\\n  ovs_execute_actions+0xd5/0x3b0 [openvswitch]\\n  ovs_packet_cmd_execute+0x949/0xdb0 [openvswitch]\\n  genl_family_rcv_msg_doit+0x1d6/0x2b0\\n  genl_family_rcv_msg+0x336/0x580\\n  genl_rcv_msg+0x9f/0x130\\n  netlink_rcv_skb+0x11f/0x370\\n  genl_rcv+0x24/0x40\\n  netlink_unicast+0x73e/0xaa0\\n  netlink_sendmsg+0x744/0xbf0\\n  __sys_sendto+0x3d6/0x450\\n  do_syscall_64+0x79/0x2c0\\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\\n  \u003c/TASK\u003e\\n\\nLet\u0027s add some checks that the attribute is properly sized and it\u0027s\\nthe only one attribute inside the action.  Technically, there is no\\nreal reason for OVS_KEY_ATTR_NSH to be there, as we know that we\u0027re\\npushing an NSH header already, it just creates extra nesting, but\\nthat\u0027s how uAPI works today.  So, keeping as it is.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.248\", \"versionStartIncluding\": \"4.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.198\", \"versionStartIncluding\": \"4.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.160\", \"versionStartIncluding\": \"4.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.120\", \"versionStartIncluding\": \"4.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.64\", \"versionStartIncluding\": \"4.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.18.3\", \"versionStartIncluding\": \"4.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.19\", \"versionStartIncluding\": \"4.15\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-11T21:53:18.670Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-68785\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-06-16T19:22:11.052Z\", \"dateReserved\": \"2025-12-24T10:30:51.036Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2026-01-13T15:28:58.930Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…