Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68209

13
FAUCET Score

CVE-2025-68209 describes a vulnerability in the Linux kernel's mlx5 driver where incorrect default values during Completion Queue (CQ) creation could lead to a null pointer exception. Specifically, polling-only kernel CQs could be triggered by an interrupt and call a completion function intended for user CQs. While the CVSS score is not provided, the FAUCET Risk Score of 7/100 suggests a low to moderate risk, and the EPSS score indicates very low exploitability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.0CNA affecteddefault affected
LinuxLinux
>= cdd04f4d4d71cbf93d0d9abe63bc838f47c467fa, < 08469f5393a1a39f26a6e2eb2e8c33187665c1f4, >= cdd04f4d4d71cbf93d0d9abe63bc838f47c467fa, < e5eba42f01340f73888dfe560be2806057c25913CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (7)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (3)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-68209Moderate

kernel: mlx5: Fix default values in create CQ

Dec 16, 2025
microsoft2025-Dec/CVE-2025-68209Moderate

mlx5: Fix default values in create CQ

Dec 9, 2025

References

git.kernel.org / stable/c/08469f5393a1a39f26a6e2eb2e8c33187665c1f4
git.kernel.org / stable/c/e5eba42f01340f73888dfe560be2806057c25913