#VU121378 Use-after-free in Linux kernel - CVE-2025-68801
Published: January 14, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the mlxsw_sp_neigh_entry_alloc(), mlxsw_sp_nexthop_dead_neigh_replace(), mlxsw_sp_nexthop_neigh_init() and mlxsw_sp_nexthop_neigh_fini() functions in drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c. A local user can escalate privileges on the system.
Remediation
External links
- https://git.kernel.org/stable/c/4a3c569005f42ab5e5b2ad637132a33bf102cc08
- https://git.kernel.org/stable/c/675c5aeadf6472672c472dc0f26401e4fcfbf254
- https://git.kernel.org/stable/c/8b0e69763ef948fb872a7767df4be665d18f5fd4
- https://git.kernel.org/stable/c/c437fbfd4382412598cdda1f8e2881b523668cc2
- https://git.kernel.org/stable/c/ed8141b206bdcfd5d0b92c90832eeb77b7a60a0a