Review reviewHigh

CVE-2025-68241

Linux

In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe The sit driver's packet transmission path calls: sit_tunnel_xmit() -> update_or_create_fnhe(), which lead to fnhe_remove_oldest() being called to delete entries exceeding FNHE_RECLAIM_DEPTH+random. The race window is between fnhe_remove_oldest() selecting fnheX for deletion and the subsequent kfree_rcu(). During this time, the concurrent path's __mkroute_output() -> find_exception() can fetch the soon-to-be-deleted fnheX, and rt_bind_exception() then binds i...

CVSS
7.5
EPSS
0.41%
34.0% percentile
CISA KEV
Not listed
Published
2025.12.17
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.41%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe The sit driver's packet transmission path calls: sit_tunnel_xmit() -> update_or_create_fnhe(), which lead to fnhe_remove_oldest() being called to delete entries exceeding FNHE_RECLAIM_DEPTH+random. The race window is between fnhe_remove_oldest() selecting fnheX for deletion and the subsequent kfree_rcu(). During this time, the concurrent path's __mkroute_output() -> find_exception() can fetch the soon-to-be-deleted fnheX, and rt_bind_exception() then binds i...

Affected product and versions

Product
Linux
Affected versions
>= e46e23c289f62ccd8e2230d9ce652072d777ff30 < 69d35c12168f9c59b159ae566f77dfad9f96d7ca, >= 5867e20e1808acd0c832ddea2587e5ee49813874 < 4b7210da22429765d19460d38c30eeca72656282, >= 67d6d681e15b578c1725bad8ad079e05d1c48a8e < 298f1e0694ab4edb6092d66efed93c4554e6ced1, >= 67d6d681e15b578c1725bad8ad079e05d1c48a8e < b8a44407bdaf2f0c5505cc7d9fc7d8da90cf9a94, >= 67d6d681e15b578c1725bad8ad079e05d1c48a8e < 041ab9ca6e80d8f792bb69df28ebf1ef39c06af8, >= 67d6d681e15b578c1725bad8ad079e05d1c48a8e < b84f083f50ecc736a95091691339a1b363962f0e, >= 67d6d681e15b578c1725bad8ad079e05d1c48a8e < 0fd16ed6dc331636fb2a874c42d2f7d3156f7ff0, >= 67d6d681e15b578c1725bad8ad079e05d1c48a8e < ac1499fcd40fe06479e9b933347b837ccabc2a40, >= bed8941fbdb72a61f6348c4deb0db69c4de87aca, >= f10ce783bcc4d8ea454563a7d56ae781640e7dcb, >= f484595be6b7ef9d095a32becabb5dae8204fb2a, >= 3e6bd2b583f18da9856fc9741ffa200a74a52cba, >= 5ae06218331f39ec45b5d039aa7cb3ddd4bb8008, >= 4589a12dcf80af31137ef202be1ff4a321707a73, >= 5.4.146 < 5.4.302, >= 5.10.65 < 5.10.247, >= 4.4.284 < 4.5, >= 4.9.283 < 4.10, >= 4.14.247 < 4.15, >= 4.19.207 < 4.20
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
Not available