Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68360

11
FAUCET Score

CVE-2025-68360 is a vulnerability in the Linux kernel's mt76 Wi-Fi driver, specifically affecting devices that utilize both "wed" and "wed_hif2" for traffic offloading, such as the MT7996. The flaw arises from the driver incorrectly assuming the use of the primary "wed" device in callbacks, leading to a kernel crash if "wed_hif2" is active (e.g., on a 6GHz link). This results in a denial-of-service condition. The vulnerability has a FAUCET Risk Score of 7/100, indicating a low severity. The attack vector is likely local, requiring specific hardware configurations and potentially privileged access to trigger the kernel crash. The complexity appears moderate, given the specific driver interaction required. The primary impact is system instability and denial of service. There is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. While there is some community discussion and media coverage, it primarily pertains to security updates rather than active exploitation. This CVE is not listed on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.8CNA affecteddefault affected
LinuxLinux
>= 83eafc9251d6d30574b629ac637c56d168fcbdd9, < 385aab8fccd7a8746b9f1a17f3c1e38498a14bc7, >= 83eafc9251d6d30574b629ac637c56d168fcbdd9, < ab94ecb997fd1bbc501a0116c7aad51556b67c86, >= 83eafc9251d6d30574b629ac637c56d168fcbdd9, < d582d0e988d696698c94edf097062bb987ae592cCNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

Remediation

Patch Available

Vendor Patches (17)

ubuntupatch availablevia ubuntu_usn
Product: linux-oem-6.17 (noble)Fixed in: 6.17.0-1017.17
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.17 (noble)Fixed in: 6.17.0-1010.10~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-raspi (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-aws-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-hwe-6.17 (noble)Fixed in: 6.17.0-19.19~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux (questing)Fixed in: 6.17.0-19.19
ubuntupatch availablevia ubuntu_usn
Product: linux-aws (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.3
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime (questing)Fixed in: 6.17.0-1008.9
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime-6.17 (noble)Fixed in: 6.17.0-1008.9~24.04.1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel

Vendor Advisories (7)

ubuntuUSN-8152-1

Linux kernel (OEM) vulnerabilities

Apr 6, 2026
ubuntuUSN-8094-5

Linux kernel (Raspberry Pi) vulnerabilities

Apr 1, 2026
ubuntuUSN-8094-4

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8094-3

Linux kernel (Real-time) vulnerabilities

Mar 23, 2026
ubuntuUSN-8094-2

Linux kernel vulnerabilities

Mar 17, 2026
ubuntuUSN-8094-1

Linux kernel vulnerabilities

Mar 16, 2026
redhatCVE-2025-68360Moderate

kernel: wifi: mt76: wed: use proper wed reference in mt76 wed driver callabacks

Dec 24, 2025

References

git.kernel.org / stable/c/385aab8fccd7a8746b9f1a17f3c1e38498a14bc7
git.kernel.org / stable/c/ab94ecb997fd1bbc501a0116c7aad51556b67c86
git.kernel.org / stable/c/d582d0e988d696698c94edf097062bb987ae592c