Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-68320

7.5 · HIGH
Published Dec 16, 2025 EPSS 0.40% (34th pctl)

Overview

CVE-2025-68320 is a high-severity vulnerability. It was published on December 16, 2025 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

lan966x: Fix sleeping in atomic context

The following warning was seen when we try to connect using ssh to the device.

BUG: sleeping function called from invalid context at kernel/locking/mutex.c:575

in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 104, name: dropbear

preempt_count: 1, expected: 0

INFO: lockdep is turned off.

CPU: 0 UID: 0 PID: 104 Comm: dropbear Tainted: G W 6.18.0-rc2-00399-g6f1ab1b109b9-dirty #530 NONE

Tainted: [W]=WARN

Hardware name: Generic DT based system

Call trace:

unwind_backtrace from show_stack+0x10/0x14

show_stack from dump_stack_lvl+0x7c/0xac

dump_stack_lvl from __might_resched+0x16c/0x2b0

__might_resched from __mutex_lock+0x64/0xd34

__mutex_lock from mutex_lock_nested+0x1c/0x24

mutex_lock_nested from lan966x_stats_get+0x5c/0x558

lan966x_stats_get from dev_get_stats+0x40/0x43c

dev_get_stats from dev_seq_printf_stats+0x3c/0x184

dev_seq_printf_stats from de

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2025-68320?

CVE-2025-68320 is a high-severity vulnerability. It was published on December 16, 2025 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2025-68320?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2025-68320?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-68320?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-68320 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.