CVE-2025-68799
In the Linux kernel, the following vulnerability has been resolved:
caif: fix integer underflow in cffrml_receive()
The cffrml_receive() function extracts a length field from the packet header and, when FCS is disabled, subtracts 2 from this length without validating that len >= 2.
If an attacker sends a malicious packet with a length field of 0 or 1 to an interface with FCS disabled, the subtraction causes an integer underflow.
This can lead to memory exhaustion and kernel instability, potential information disclosure if padding contains uninitialized kernel memory.
Fix this by validating that len >= 2 before performing the subtraction.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1005Data from Local Systemcollection60 %
AV:A (red adyacente) sin privilegios → T1210. Integer underflow causa agotamiento de memoria (DoS) e informac. disclosure; validación faltante en cffrml_receive() lo sustenta.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/21fdcc00656a60af3c7aae2dea8dd96abd35519c
- https://git.kernel.org/stable/c/4ec29714aa4e0601ea29d2f02b461fc0ac92c2c3
- https://git.kernel.org/stable/c/785c7be6361630070790f6235b696da156ac71b3
- https://git.kernel.org/stable/c/8a11ff0948b5ad09b71896b7ccc850625f9878d1
- https://git.kernel.org/stable/c/c54091eec6fed19e94182aa05dd6846600a642f7
- https://git.kernel.org/stable/c/f407f1c9f45bbf5c99fd80b3f3f4a94fdbe35691
- https://git.kernel.org/stable/c/f818cd472565f8b0c2c409b040e0121c5cf8592c
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68799",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "f407f1c9f45bbf5c99fd80b3f3f4a94fdbe35691",
"versionType": "git"
},
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "c54091eec6fed19e94182aa05dd6846600a642f7",
"versionType": "git"
},
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "785c7be6361630070790f6235b696da156ac71b3",
"versionType": "git"
},
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "f818cd472565f8b0c2c409b040e0121c5cf8592c",
"versionType": "git"
},
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "4ec29714aa4e0601ea29d2f02b461fc0ac92c2c3",
"versionType": "git"
},
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "21fdcc00656a60af3c7aae2dea8dd96abd35519c",
"versionType": "git"
},
{
"status": "affected",
"version": "b482cd2053e3b90a7b33a78c63cdb6badf2ec383",
"lessThan": "8a11ff0948b5ad09b71896b7ccc850625f9878d1",
"versionType": "git"
}
],
"programFiles": [
"net/caif/cffrml.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.35"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.35",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.248",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.198",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.64",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.3",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/caif/cffrml.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-01-13T16:16:01.907",
"references": [
{
"url": "https://git.kernel.org/stable/c/21fdcc00656a60af3c7aae2dea8dd96abd35519c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4ec29714aa4e0601ea29d2f02b461fc0ac92c2c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/785c7be6361630070790f6235b696da156ac71b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8a11ff0948b5ad09b71896b7ccc850625f9878d1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c54091eec6fed19e94182aa05dd6846600a642f7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f407f1c9f45bbf5c99fd80b3f3f4a94fdbe35691",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f818cd472565f8b0c2c409b040e0121c5cf8592c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncaif: fix integer underflow in cffrml_receive()\n\nThe cffrml_receive() function extracts a length field from the packet\nheader and, when FCS is disabled, subtracts 2 from this length without\nvalidating that len >= 2.\n\nIf an attacker sends a malicious packet with a length field of 0 or 1\nto an interface with FCS disabled, the subtraction causes an integer\nunderflow.\n\nThis can lead to memory exhaustion and kernel instability, potential\ninformation disclosure if padding contains uninitialized kernel memory.\n\nFix this by validating that len >= 2 before performing the subtraction."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ncaif: corrige desbordamiento negativo de enteros en cffrml_receive()\n\nLa función cffrml_receive() extrae un campo de longitud del encabezado del paquete y, cuando FCS está deshabilitado, resta 2 a esta longitud sin validar que len >= 2.\n\nSi un atacante envía un paquete malicioso con un campo de longitud de 0 o 1 a una interfaz con FCS deshabilitado, la resta causa un desbordamiento negativo de enteros.\n\nEsto puede llevar a agotamiento de memoria e inestabilidad del kernel, potencial revelación de información si el relleno contiene memoria del kernel no inicializada.\n\nSoluciona esto validando que len >= 2 antes de realizar la resta."
}
],
"lastModified": "2026-07-30T06:24:45.387",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}