In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations leak socket When a handshake… (CVE-2025-68775)
A critical vulnerability in the Linux kernel's network handshake code allows duplicate handshake cancellations to leak socket references, leading to a reference count underflow. This occurs when a handshake request is cancelled multiple times but not properly marked as completed, causing improper socket reference handling. The issue can arise in scenarios such as SUNRPC client-server TLS handshake timeouts. The vulnerability has been resolved by adding a mechanism to detect and handle duplicate cancellations correctly.
AI Analysis
Technical Summary
The Linux kernel vulnerability (CVE-2025-68775) involves improper handling of duplicate handshake cancellation requests in the network handshake subsystem. When a handshake request is cancelled, it is removed from one internal list but remains in another until destruction. If a second cancellation occurs before the handshake is marked completed, the code erroneously adds another reference to the socket, causing a reference count underflow. This flaw can be triggered by handshake timeouts, such as in SUNRPC TLS handshakes where the client fails to complete the handshake. The fix involves setting a flag (HANDSHAKE_F_REQ_COMPLETED) during cancellation to detect and prevent duplicate processing.
Potential Impact
This vulnerability can cause a reference count underflow on socket objects, potentially leading to memory corruption, denial of service, or other undefined kernel behavior. The CVSS vector indicates high impact on confidentiality, integrity, and availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability description states it has been resolved by adding a test_and_set_bit for the HANDSHAKE_F_REQ_COMPLETED flag to detect duplicate cancellations. Security teams should monitor for official Linux kernel updates addressing CVE-2025-68775 and apply them promptly once available.
In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations leak socket When a handshake… (CVE-2025-68775)
Description
A critical vulnerability in the Linux kernel's network handshake code allows duplicate handshake cancellations to leak socket references, leading to a reference count underflow. This occurs when a handshake request is cancelled multiple times but not properly marked as completed, causing improper socket reference handling. The issue can arise in scenarios such as SUNRPC client-server TLS handshake timeouts. The vulnerability has been resolved by adding a mechanism to detect and handle duplicate cancellations correctly.
CVSS v3.1
Score 9.8critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability (CVE-2025-68775) involves improper handling of duplicate handshake cancellation requests in the network handshake subsystem. When a handshake request is cancelled, it is removed from one internal list but remains in another until destruction. If a second cancellation occurs before the handshake is marked completed, the code erroneously adds another reference to the socket, causing a reference count underflow. This flaw can be triggered by handshake timeouts, such as in SUNRPC TLS handshakes where the client fails to complete the handshake. The fix involves setting a flag (HANDSHAKE_F_REQ_COMPLETED) during cancellation to detect and prevent duplicate processing.
Potential Impact
This vulnerability can cause a reference count underflow on socket objects, potentially leading to memory corruption, denial of service, or other undefined kernel behavior. The CVSS vector indicates high impact on confidentiality, integrity, and availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability description states it has been resolved by adding a test_and_set_bit for the HANDSHAKE_F_REQ_COMPLETED flag to detect duplicate cancellations. Security teams should monitor for official Linux kernel updates addressing CVE-2025-68775 and apply them promptly once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jpgq-r68h-x9q2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-68775"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a6b72d19c2644c7f8477395
Added to database: 07/30/2026, 15:50:41 UTC
Last enriched: 07/30/2026, 19:10:11 UTC
Last updated: 09/10/2026, 19:38:44 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.