CVE-2025-68209 describes a vulnerability in the Linux kernel's mlx5 driver where incorrect default values during Completion Queue (CQ) creation could lead to a null pointer exception. Specifically, polling-only kernel CQs could be triggered by an interrupt and call a completion function intended for user CQs. While the CVSS score is not provided, the FAUCET Risk Score of 7/100 suggests a low to moderate risk, and the EPSS score indicates very low exploitability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.0CNA affecteddefault affected | |
| Linux | Linux | >= cdd04f4d4d71cbf93d0d9abe63bc838f47c467fa, < 08469f5393a1a39f26a6e2eb2e8c33187665c1f4, >= cdd04f4d4d71cbf93d0d9abe63bc838f47c467fa, < e5eba42f01340f73888dfe560be2806057c25913CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.