CVE-2025-68302: Linux
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: fix potential NULL dereference in sxgbe_rx() Currently, when skb is null, the driver prints an error and then dereferences skb on the next line. To fix this, let's add a 'break' after the error message to switch to sxgbe_rx_refill(), which is similar to the approach taken by the other drivers in this particular case, e.g. calxeda with xgmac_rx(). Found during a code review.
Affected products
- Linux Linux: from 3.15, before 5.10.247 (fixed in 5.10.247); from 5.11, before 5.15.197 (fixed in 5.15.197); from 5.16, before 6.1.159 (fixed in 6.1.159); from 6.2, before 6.6.119 (fixed in 6.6.119); from 6.7, before 6.12.61 (fixed in 6.12.61); from 6.13, before 6.17.11 (fixed in 6.17.11)
Published 2025-12-16. Last modified 2026-07-30.