CVE-2025-68182: Linux

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link() This code frees "link" by calling kfree_rcu(link, rcu_head) and then it dereferences "link" to get the "link->fw_id". Save the "link->fw_id" first to avoid a potential use after free.

Affected products

  • Linux Linux: from 6.15, before 6.17.8 (fixed in 6.17.8)

Published 2025-12-16. Last modified 2026-07-30.