Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-68811— svcrdma: use rc_pageoff for memcpy byte offset

CVSS 9.8 · Critical EPSS 0.46% · P38

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux8e122582680c6f8acd686a5a2af9c0e46fe90f2d< e8623e9c451e23d84b870811f42fd872b4089ef6affected
8e122582680c6f8acd686a5a2af9c0e46fe90f2d< 2a77c8dd49bccf0ca232be7c836cec1209abb8daaffected
8e122582680c6f8acd686a5a2af9c0e46fe90f2d< a8ee9099f30654917aa68f55d707b5627e1dbf77affected
6.8affected
< 6.8unaffected
6.12.64≤ 6.12.*unaffected
6.18.3≤ 6.18.*unaffected
6.19≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-68811

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
svcrdma: use rc_pageoff for memcpy byte offset
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc_rdma_copy_inline_range added rc_curpage (page index) to the page base instead of the byte offset rc_pageoff. Use rc_pageoff so copies land within the current page. Found by ZeroPath (https://zeropath.com)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于复制内联范围时使用了错误的偏移量,可能导致数据复制位置错误。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 8e122582680c6f8acd686a5a2af9c0e46fe90f2d ~ e8623e9c451e23d84b870811f42fd872b4089ef6 -
LinuxLinux 6.8 -

II. Public POCs for CVE-2025-68811

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-68811

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-01-13 · 93 CVEs total

CVE-2025-710689.8 CRITICALsvcrdma: bound check rq_pages index in inline path
CVE-2025-687949.8 CRITICALiomap: adjust read range correctly for non-block-aligned positions
CVE-2025-688179.8 CRITICALksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
CVE-2025-687759.8 CRITICALnet/handshake: duplicate handshake cancellations leak socket
CVE-2025-688099.1 CRITICALksmbd: vfs: fix race on m_flags in vfs_cache
CVE-2025-710939.1 CRITICALe1000: fix OOB in e1000_tbi_should_accept()
CVE-2025-710959.1 CRITICALnet: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-688188.8 HIGHscsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"
CVE-2025-710728.2 HIGHshmem: fix recovery on rename failures
CVE-2025-687998.1 HIGHcaif: fix integer underflow in cffrml_receive()
CVE-2025-688038.0 HIGHNFSD: NFSv4 file creation neglects setting ACL
CVE-2025-688057.8 HIGHfuse: fix io-uring list corruption for terminated non-committed requests
CVE-2025-710787.8 HIGHpowerpc/64s/slb: Fix SLB multihit issue during SLB preload
CVE-2025-688017.8 HIGHmlxsw: spectrum_router: Fix neighbour use-after-free
CVE-2025-710827.8 HIGHBluetooth: btusb: revert use of devm_kzalloc in btusb
CVE-2025-688107.8 HIGHKVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot
CVE-2025-687957.8 HIGHethtool: Avoid overflowing userspace buffer on stats query
CVE-2025-687937.8 HIGHdrm/amdgpu: fix a job->pasid access race in gpu recovery
CVE-2025-688227.8 HIGHInput: alps - fix use-after-free bugs caused by dev3_register_work
CVE-2025-687927.8 HIGHtpm2-sessions: Fix out of range indexing in name_size

Showing top 20 of 93 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-68811

No comments yet


Leave a comment