Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68359

12
FAUCET Score

CVE-2025-68359 describes a double-free vulnerability in the Linux kernel's Btrfs filesystem, specifically within the qgroup record handling when adding delayed reference heads. This flaw could lead to memory corruption due to an object being freed twice. While no CVSS score is provided, its FAUCET Risk Score is 7/100, indicating a low-to-moderate risk. There is no evidence of active exploitation, publicly available exploit code, or Metasploit/Nuclei modules. Community discussion and media coverage are minimal, suggesting limited attention.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.12CNA affecteddefault affected
LinuxLinux
>= 6ef8fbce010421bf742b12b8f8f2b2d2ff154845, < 364685c4c2d9c9f4408d95451bcf42fdeebc3ebb, >= 6ef8fbce010421bf742b12b8f8f2b2d2ff154845, < 725e46298876a2cc1f1c3fb22ba69d29102c3ddf, >= 6ef8fbce010421bf742b12b8f8f2b2d2ff154845, < 7617680769e3119dfb3b43a2b7c287ce2242211cCNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
7.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

Remediation

Patch Available

Vendor Patches (14)

ubuntupatch availablevia ubuntu_usn
Product: linux-aws-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-hwe-6.17 (noble)Fixed in: 6.17.0-19.19~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux (questing)Fixed in: 6.17.0-19.19
ubuntupatch availablevia ubuntu_usn
Product: linux-aws (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.3
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime (questing)Fixed in: 6.17.0-1008.9
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime-6.17 (noble)Fixed in: 6.17.0-1008.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.17 (noble)Fixed in: 6.17.0-1010.10~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-raspi (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-oem-6.17 (noble)Fixed in: 6.17.0-1017.17

Vendor Advisories (7)

ubuntuUSN-8152-1

Linux kernel (OEM) vulnerabilities

Apr 6, 2026
ubuntuUSN-8094-5

Linux kernel (Raspberry Pi) vulnerabilities

Apr 1, 2026
ubuntuUSN-8094-4

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8094-3

Linux kernel (Real-time) vulnerabilities

Mar 23, 2026
ubuntuUSN-8094-2

Linux kernel vulnerabilities

Mar 17, 2026
ubuntuUSN-8094-1

Linux kernel vulnerabilities

Mar 16, 2026
redhatCVE-2025-68359Low

kernel: btrfs: fix double free of qgroup record after failure to add delayed ref head

Dec 24, 2025

References

git.kernel.org / stable/c/364685c4c2d9c9f4408d95451bcf42fdeebc3ebb
git.kernel.org / stable/c/725e46298876a2cc1f1c3fb22ba69d29102c3ddf
git.kernel.org / stable/c/7617680769e3119dfb3b43a2b7c287ce2242211c