In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup Raw IP… (CVE-2025-68192)
A critical vulnerability in the Linux kernel's net: usb: qmi_wwan component was resolved by initializing the MAC header offset in qmimux_rx_fixup. Raw IP packets previously left the MAC header uninitialized, which could cause kernel panics on ARM64 and ARM architectures when subsystems like xfrm accessed this offset due to strict alignment checks. This issue specifically affected IPsec operations over the qmimux0 interface and could lead to system crashes.
AI Analysis
Technical Summary
The vulnerability CVE-2025-68192 in the Linux kernel involves the net: usb: qmi_wwan driver failing to initialize the MAC header offset in the qmimux_rx_fixup function. Raw IP packets do not have a MAC header, so skb->mac_header remained uninitialized. When subsystems such as xfrm accessed this uninitialized offset, it triggered kernel panics on ARM64 and ARM platforms due to strict alignment enforcement. The flaw was fixed by explicitly initializing the MAC header to prevent these crashes, particularly when running IPsec over the qmimux0 interface.
Potential Impact
Exploitation of this vulnerability can cause kernel panics leading to denial of service on affected ARM64 and ARM systems running the vulnerable Linux kernel versions. The impact includes system instability and potential disruption of network services, especially those using IPsec over the qmimux0 interface. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by initializing the MAC header offset in the qmimux_rx_fixup function. Users should apply the official kernel updates that include this fix. Since this is a kernel-level issue, upgrading to a patched kernel version is the recommended remediation. Patch status is not explicitly confirmed in the provided data; therefore, check the official Linux kernel advisories or vendor updates for the exact fixed versions and apply them accordingly.
In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup Raw IP… (CVE-2025-68192)
Description
A critical vulnerability in the Linux kernel's net: usb: qmi_wwan component was resolved by initializing the MAC header offset in qmimux_rx_fixup. Raw IP packets previously left the MAC header uninitialized, which could cause kernel panics on ARM64 and ARM architectures when subsystems like xfrm accessed this offset due to strict alignment checks. This issue specifically affected IPsec operations over the qmimux0 interface and could lead to system crashes.
CVSS v3.1
Score 9.8critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2025-68192 in the Linux kernel involves the net: usb: qmi_wwan driver failing to initialize the MAC header offset in the qmimux_rx_fixup function. Raw IP packets do not have a MAC header, so skb->mac_header remained uninitialized. When subsystems such as xfrm accessed this uninitialized offset, it triggered kernel panics on ARM64 and ARM platforms due to strict alignment enforcement. The flaw was fixed by explicitly initializing the MAC header to prevent these crashes, particularly when running IPsec over the qmimux0 interface.
Potential Impact
Exploitation of this vulnerability can cause kernel panics leading to denial of service on affected ARM64 and ARM systems running the vulnerable Linux kernel versions. The impact includes system instability and potential disruption of network services, especially those using IPsec over the qmimux0 interface. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by initializing the MAC header offset in the qmimux_rx_fixup function. Users should apply the official kernel updates that include this fix. Since this is a kernel-level issue, upgrading to a patched kernel version is the recommended remediation. Patch status is not explicitly confirmed in the provided data; therefore, check the official Linux kernel advisories or vendor updates for the exact fixed versions and apply them accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cff9-qhwv-r7q7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-68192"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a6b72d39c2644c7f847861e
Added to database: 07/30/2026, 15:50:43 UTC
Last enriched: 07/30/2026, 18:25:23 UTC
Last updated: 09/10/2026, 19:38:49 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.