CVE-2025-68374

Linux Kernel - Use-After-Free in md_wakeup_thread

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: md: fix rcu protection in md_wakeup_thread We attempted to use RCU to protect the pointer 'thread', but directly passed the value when calling md_wakeup_thread(). This means that the RCU pointer has been acquired before rcu_read_lock(), which renders rcu_read_lock() ineffective and could lead to a use-after-free.

Scores

EPSS 0.0002
EPSS Percentile 7.2%

Details

Status published
Products (13)
linux/Kernel 6.13.0 - 6.17.13linux
linux/Kernel 6.18.0 - 6.18.2linux
linux/Kernel 6.5.0 - 6.12.63linux
Linux/Linux < 6.5
Linux/Linux 4469315439827290923fce4f3f672599cabeb366 - 0dc76205549b4c25705e54345f211b9f66e018a0
Linux/Linux 4469315439827290923fce4f3f672599cabeb366 - 21989cb5034c835b212385a2afadf279d8069da0
Linux/Linux 4469315439827290923fce4f3f672599cabeb366 - a4bd1caf591faeae44cb10b6517e7dacb5139bda
Linux/Linux 4469315439827290923fce4f3f672599cabeb366 - f98b191f78124405294481dea85f8a22a3eb0a59
Linux/Linux 6.12.63 - 6.12.*
Linux/Linux 6.17.13 - 6.17.*
... and 3 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026