Junglewise Threat Intelligence

CVE-2025-68301: Linux Kernel Atlantic driver out-of-bounds write in RX path

CVE-2025-68301 · Severity: critical · CVSS 9.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Atlantic network driver could allow a remote attacker to crash the system. The issue occurs when the driver processes specially crafted, large network packets that exceed internal memory limits. This can lead to a kernel panic, resulting in a complete system outage.

Technical details

An out-of-bounds write vulnerability exists in the Atlantic (Aquantia) network driver's RX path within the Linux kernel. The driver fails to properly validate the number of fragments in multi-descriptor packets before calling skb_add_rx_frag(), allowing the fragment index to exceed the MAX_SKB_FRAGS limit. This results in an out-of-bounds write in skb_add_rx_frag_netmem(), leading to a kernel panic. The vulnerability can be triggered by receiving large packets over the network. Patches have been released for various stable kernel branches to ensure all fragments are accounted for before processing.

Affected products

  • Linux Linux Kernel 6aecbba12b5c to 5ffcb7b890f6

Timeline

  • 2025-11-26: patched: Initial patch submitted
  • 2025-12-16: advisory: CVE-2025-68301 published

References

Related threats