Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68262

11
FAUCET Score

CVE-2025-68262 describes a double-free vulnerability in the Linux kernel's crypto/zstd module. This flaw occurs because per-CPU ZSTD streams are incorrectly freed multiple times when different transform objects (tfms) are destroyed, rather than being managed at the module level. The vulnerability has no assigned CVSS score, but its FAUCET Risk Score is 7/100, indicating a low severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.17CNA affecteddefault affected
LinuxLinux
>= f5ad93ffb54119a8dc5e18f070624d4ead586969, < 48bc9da3c97c15f1ea24934bcb3b736acd30163d, >= f5ad93ffb54119a8dc5e18f070624d4ead586969, < dc0f4509b0ed5d82bef78e058db0ac4df04d0695, >= f5ad93ffb54119a8dc5e18f070624d4ead586969, < e983feaa79de1e46c9087fb9f02fedb0e5397ce6CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

Remediation

Patch Available

Vendor Patches (14)

ubuntupatch availablevia ubuntu_usn
Product: linux-aws-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-hwe-6.17 (noble)Fixed in: 6.17.0-19.19~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux (questing)Fixed in: 6.17.0-19.19
ubuntupatch availablevia ubuntu_usn
Product: linux-aws (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.3
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime (questing)Fixed in: 6.17.0-1008.9
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime-6.17 (noble)Fixed in: 6.17.0-1008.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.17 (noble)Fixed in: 6.17.0-1010.10~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-raspi (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-oem-6.17 (noble)Fixed in: 6.17.0-1017.17

Vendor Advisories (7)

ubuntuUSN-8152-1

Linux kernel (OEM) vulnerabilities

Apr 6, 2026
ubuntuUSN-8094-5

Linux kernel (Raspberry Pi) vulnerabilities

Apr 1, 2026
ubuntuUSN-8094-4

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8094-3

Linux kernel (Real-time) vulnerabilities

Mar 23, 2026
ubuntuUSN-8094-2

Linux kernel vulnerabilities

Mar 17, 2026
ubuntuUSN-8094-1

Linux kernel vulnerabilities

Mar 16, 2026
redhatCVE-2025-68262

crypto: zstd - fix double-free in per-CPU stream cleanup

Dec 16, 2025

References

git.kernel.org / stable/c/48bc9da3c97c15f1ea24934bcb3b736acd30163d
git.kernel.org / stable/c/dc0f4509b0ed5d82bef78e058db0ac4df04d0695
git.kernel.org / stable/c/e983feaa79de1e46c9087fb9f02fedb0e5397ce6