A flaw in the Linux kernel crypto asymmetric_keys subsystem, tracked as CVE-2025-68724, was fixed after maintainers found that asymmetric_key_generate_id could overflow while calculating the size of key identifier data derived from X.509 certificate fields. The bug affects kernels dating back to 3.18 and could trigger a buffer overflow when processing maliciously large certificate values, including ASN.1 INTEGER serial numbers and issuer names. Upstream kernel maintainers addressed the issue by adding check_add_overflow() validation and returning ERR_PTR(-EOVERFLOW) when oversized input is detected, with fixes released across multiple stable branches including 6.12.63, 6.17.13, 6.18.2, and 6.19-rc1.
Red Hat published the vulnerability as a Moderate issue with a CVSS 7.1 rating and shipped remediations through multiple RHEL 8, 9, and 10 kernel errata. One of the affected advisories, RHSA-2026:23237, delivered updated kernel packages for several RHEL 9.4 SAP-related variants and included CVE-2025-68724 among a broader set of 12 kernel fixes; Red Hat said systems must be rebooted after installation for the updates to take effect. The vendor tied the flaw to CWE-190 integer overflow and advised customers to apply the updated kernel packages rather than rely on partial fixes.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat's CVE page for CVE-2025-68724 described the flaw as an integer overflow in asymmetric_key_generate_id that could cause a buffer overflow from malicious X.509 certificate fields. Red Hat rated the issue Moderate and assigned it a CVSS v3 base score of 7.1.
Red Hat fixed CVE-2025-68724 for Red Hat Enterprise Linux 8 through RHSA-2026:13577 and RHSA-2026:13578. These advisories covered RHEL 8 kernel and kernel-rt packages.
On 2025-12-24, the Linux kernel CVE team announced CVE-2025-68724, describing an integer overflow in asymmetric_key_generate_id in the crypto asymmetric_keys subsystem that could lead to a buffer overflow when processing malicious X.509 certificate fields. The advisory said the issue had been fixed in multiple kernel branches including 6.12.63, 6.17.13, 6.18.2, and 6.19-rc1.
Red Hat fixed CVE-2025-68724 for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On in RHSA-2026:47633. The Red Hat CVE entry dates these fixes to 2026-07-30.
Red Hat fixed CVE-2025-68724 for Red Hat Enterprise Linux 10.0 Extended Update Support in RHSA-2026:39371. The Red Hat CVE entry dates this fix to 2026-07-14.
Red Hat fixed CVE-2025-68724 for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and 8.8 Telecommunications Update Service in RHSA-2026:26563. The Red Hat CVE entry dates these fixes to 2026-06-17.
Red Hat fixed CVE-2025-68724 for Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On and 8.6 Advanced Mission Critical Update Support in RHSA-2026:25533. The Red Hat CVE entry dates these fixes to 2026-06-12.
On 2026-06-04, Red Hat published RHSA-2026:23237, an Important kernel security advisory for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related 9.4 variants. The update included fixes for 12 kernel vulnerabilities, including CVE-2025-68724, and required a reboot after installation.
Red Hat fixed CVE-2025-68724 for Red Hat Enterprise Linux 10 in RHSA-2026:19569. The Red Hat CVE entry lists this as the RHEL 10 kernel package fix for the vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.