CVE-2025-68800: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats
Cited commit added a dedicated mutex (instead of RTNL) to protect the
multicast route list, so that it will not change while the driver
periodically traverses it in order to update the kernel about multicast
route stats that were queried from the device.
One instance of list entry deletion (during route replace) was missed
and it can result in a use-after-free [1].
Fix by acquiring the mutex before deleting the entry from the list and
releasing it afterwards.
[1]
BUG: KASAN: slab-use-after-free in mlxsw_sp_mr_stats_update+0x4a5/0x540 drivers/net/ethernet/mellanox/mlxsw/spectrum_mr.c:1006 [mlxsw_spectrum]
Read of size 8 at addr ffff8881523c2fa8 by task kworker/2:5/22043
CPU: 2 UID: 0 PID: 22043 Comm: kworker/2:5 Not tainted 6.18.0-rc1-custom-g1a3d6d7cd014 #1 PREEMPT(full)
Hardware name: Mellanox Technologies Ltd. MSN2010/SA002610, BIOS 5.6.5 08/24/2017
Workqueue: mlxsw_core mlxsw_sp_mr_stats_update [mlxsw_spectrum]
Call Trace:
<TASK>
dump_stack_lvl+0xba/0x110
print_report+0x174/0x4f5
kasan_report+0xdf/0x110
mlxsw_sp_mr_stats_update+0x4a5/0x540 drivers/net/ethernet/mellanox/mlxsw/spectrum_mr.c:1006 [mlxsw_spectrum]
process_one_work+0x9cc/0x18e0
worker_thread+0x5df/0xe40
kthread+0x3b8/0x730
ret_from_fork+0x3e9/0x560
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 29933:
kasan_save_stack+0x30/0x50
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
mlxsw_sp_mr_route_add+0xd8/0x4770 [mlxsw_spectrum]
mlxsw_sp_router_fibmr_event_work+0x371/0xad0 drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c:7965 [mlxsw_spectrum]
process_one_work+0x9cc/0x18e0
worker_thread+0x5df/0xe40
kthread+0x3b8/0x730
ret_from_fork+0x3e9/0x560
ret_from_fork_asm+0x1a/0x30
Freed by task 29933:
kasan_save_stack+0x30/0x50
kasan_save_track+0x14/0x30
__kasan_save_free_info+0x3b/0x70
__kasan_slab_free+0x43/0x70
kfree+0x14e/0x700
mlxsw_sp_mr_route_add+0x2dea/0x4770 drivers/net/ethernet/mellanox/mlxsw/spectrum_mr.c:444 [mlxsw_spectrum]
mlxsw_sp_router_fibmr_event_work+0x371/0xad0 drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c:7965 [mlxsw_spectrum]
process_one_work+0x9cc/0x18e0
worker_thread+0x5df/0xe40
kthread+0x3b8/0x730
ret_from_fork+0x3e9/0x560
ret_from_fork_asm+0x1a/0x30
Security readout for executives and security teams
Plain-English summary
A race condition in the Linux Mellanox Spectrum network-switch driver can access memory after it has been freed while multicast routes are replaced and statistics are updated. This can destabilize or potentially compromise the kernel. The supplied CVSS score is 7.8, but exploitation requires local low-privilege access and affected driver functionality.
Executive priority
Treat as a high-priority, targeted kernel update for systems using Mellanox Spectrum multicast routing, especially shared or multi-user infrastructure. It is not evidence of an internet-wide emergency: the stated attack path is local, and active exploitation is not established. Confirm asset exposure first, then patch affected systems through supported distribution channels.
Technical view
The mlxsw Spectrum multicast-routing code failed to hold its dedicated route-list mutex during one route-replacement deletion path. A concurrent statistics worker could traverse the deleted entry, causing a slab use-after-free in mlxsw_sp_mr_stats_update. The fix surrounds that deletion with the mutex. KASAN reproduced the flaw on Mellanox Spectrum hardware.
Likely exposure
Exposure is most likely on Linux systems using the mlxsw_spectrum driver with Mellanox Spectrum hardware and multicast-routing activity. Systems without this driver or relevant hardware are unlikely to reach the vulnerable path. The bundle's version data is insufficient for reliably determining individual distribution backports.
Exploitation context
The supplied vector requires local access with low privileges, no user interaction, and low attack complexity. Neither KEV status nor the provided sources establish active exploitation or a public working exploit. The demonstrated evidence is a KASAN-detected kernel use-after-free; practical security impact beyond that crash evidence is not documented here.
Researcher notes
The trigger involves concurrent multicast-route replacement and periodic hardware-statistics traversal. The source demonstrates an eight-byte read from freed slab memory, not a documented exploitation primitive. Multiple stable commits are supplied, apparently for separate kernel branches. Exact vulnerable and fixed package versions remain distribution-dependent and should not be inferred solely from the bundle's unusual version listing.
Mitigation direction
Install a vendor-supported kernel containing the applicable stable-branch fix.
Confirm distribution backport status rather than relying only on the displayed kernel version.
Prioritize exposed multi-user systems using Mellanox Spectrum multicast routing.
If patching is delayed, consult vendor guidance for supported exposure-reduction measures.
Restrict unnecessary local account access until remediation is confirmed.
Validation and detection
Inventory kernels, Mellanox Spectrum hardware, and loaded mlxsw_spectrum modules.
Determine whether multicast routing is configured on each potentially affected system.
Match the installed kernel package against distribution security and backport records.
Verify the kernel source or package includes the applicable referenced fix commit.
Review kernel logs for mlxsw-related crashes or memory-corruption reports.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-68800 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.