Junglewise Threat Intelligence

CVE-2025-68341: Linux Kernel race condition in veth XDP return frame handling

CVE-2025-68341 · Severity: critical · CVSS 9.8 · Published 2025-12-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition vulnerability was identified in the Linux kernel's virtual Ethernet (veth) driver, which is commonly used in containerized environments like Docker and Kubernetes to manage network traffic. Under specific high-performance networking configurations, concurrent processing tasks can interfere with each other, potentially leading to system instability or unauthorized data access. This issue affects the reliability of network communications between containers and the host system.

Technical details

A race condition exists in the veth driver (drivers/net/veth.c) when using threaded-NAPI mode. The vulnerability stems from the fact that xdp_clear_return_frame_no_direct() is not designed to be nested. Following a change that moved the BPF redirect context (bpf_redirect_info) to the task_struct, concurrent calls to veth_pool()—one exiting NAPI and one starting a new NAPI instance—can access the same context simultaneously. This allows one CPU to enter the xdp_set_return_frame_no_direct() section before the previous instance has cleared it, leading to a race. The fix involves reducing the scope of the no_direct return section to ensure proper synchronization. Patches have been released for various stable kernel branches including 6.12.61 and 6.17.11.

Affected products

  • Linux Linux Kernel 6.11 to 6.12.60, 6.17 to 6.17.10

Timeline

  • 2025-11-20: patched: Initial fix committed to mainline kernel tree.
  • 2025-12-23: disclosed: CVE-2025-68341 published.

References

Related threats