CVE-2025-68737

Linux Kernel 6.18-6.18.1 - Unauthenticated Denial of Service via Memory Protection Failure

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: arm64/pageattr: Propagate return value from __change_memory_common The rodata=on security measure requires that any code path which does vmalloc -> set_memory_ro/set_memory_rox must protect the linear map alias too. Therefore, if such a call fails, we must abort set_memory_* and caller must take appropriate action; currently we are suppressing the error, and there is a real chance of such an error arising post commit a166563e7ec3 ("arm64: mm: support large block mapping when rodata=full"). Therefore, propagate any error to the caller.

Scores

EPSS 0.0002
EPSS Percentile 6.5%

Details

Status published
Products (7)
linux/Kernel 6.18.0 - 6.18.2linux
Linux/Linux < 6.18
Linux/Linux 6.18
Linux/Linux 6.18.2 - 6.18.*
Linux/Linux 6.19
Linux/Linux a166563e7ec375b38a0fd3a58f7b77e50a6bc6a8 - 3e2fc1e57a5361633a4bf4222640c6bfe41ff8ea
Linux/Linux a166563e7ec375b38a0fd3a58f7b77e50a6bc6a8 - e5efd56fa157d2e7d789949d1d64eccbac18a897
Published Dec 24, 2025
Tracked Since Feb 18, 2026