CVE-2025-68293 is a NULL pointer dereference vulnerability in the Linux kernel's huge memory management, specifically affecting shmem folios in the swap cache and truncated folios. The flaw arises from an early check on folio order that accesses a potentially NULL mapping pointer, leading to a system crash. While no specific products are listed, it impacts Linux kernel versions incorporating the problematic commit. The severity is moderate, as it requires specific memory conditions to trigger the NULL pointer dereference, likely resulting in a denial-of-service. The attack vector is internal to the kernel's memory management, suggesting a local attacker or a highly privileged process would be required to exploit it. The FAUCET Risk Score is 7/100, indicating a relatively low overall risk. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, which is typical for a significant portion of CVEs. The vulnerability is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.9CNA affecteddefault affected | |
| Linux | Linux | >= c010d47f107f609b9f4d6a103b6dfc53889049e9, < 592db83615a9f0164472ec789c2ed34ad35f732f, >= c010d47f107f609b9f4d6a103b6dfc53889049e9, < cff47b9e39a6abf03dde5f4f156f841b0c54bba0, >= c010d47f107f609b9f4d6a103b6dfc53889049e9, < d1b83fbacd4397a1d2f8c6b13427a8636ae2b307CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: mm/huge_memory: fix NULL pointer deference when splitting folio
Dec 16, 2025