CVE-2025-68359 describes a double-free vulnerability in the Linux kernel's Btrfs filesystem, specifically within the qgroup record handling when adding delayed reference heads. This flaw could lead to memory corruption due to an object being freed twice. While no CVSS score is provided, its FAUCET Risk Score is 7/100, indicating a low-to-moderate risk. There is no evidence of active exploitation, publicly available exploit code, or Metasploit/Nuclei modules. Community discussion and media coverage are minimal, suggesting limited attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.12CNA affecteddefault affected | |
| Linux | Linux | >= 6ef8fbce010421bf742b12b8f8f2b2d2ff154845, < 364685c4c2d9c9f4408d95451bcf42fdeebc3ebb, >= 6ef8fbce010421bf742b12b8f8f2b2d2ff154845, < 725e46298876a2cc1f1c3fb22ba69d29102c3ddf, >= 6ef8fbce010421bf742b12b8f8f2b2d2ff154845, < 7617680769e3119dfb3b43a2b7c287ce2242211cCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: btrfs: fix double free of qgroup record after failure to add delayed ref head
Dec 24, 2025