CVE-2025-68360 is a vulnerability in the Linux kernel's mt76 Wi-Fi driver, specifically affecting devices that utilize both "wed" and "wed_hif2" for traffic offloading, such as the MT7996. The flaw arises from the driver incorrectly assuming the use of the primary "wed" device in callbacks, leading to a kernel crash if "wed_hif2" is active (e.g., on a 6GHz link). This results in a denial-of-service condition. The vulnerability has a FAUCET Risk Score of 7/100, indicating a low severity. The attack vector is likely local, requiring specific hardware configurations and potentially privileged access to trigger the kernel crash. The complexity appears moderate, given the specific driver interaction required. The primary impact is system instability and denial of service. There is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. While there is some community discussion and media coverage, it primarily pertains to security updates rather than active exploitation. This CVE is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.8CNA affecteddefault affected | |
| Linux | Linux | >= 83eafc9251d6d30574b629ac637c56d168fcbdd9, < 385aab8fccd7a8746b9f1a17f3c1e38498a14bc7, >= 83eafc9251d6d30574b629ac637c56d168fcbdd9, < ab94ecb997fd1bbc501a0116c7aad51556b67c86, >= 83eafc9251d6d30574b629ac637c56d168fcbdd9, < d582d0e988d696698c94edf097062bb987ae592cCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: wifi: mt76: wed: use proper wed reference in mt76 wed driver callabacks
Dec 24, 2025