CVE-2025-68800 is a use-after-free vulnerability in the Linux kernel's mlxsw Spectrum multicast-routing implementation. A dedicated mutex protects the multicast route list during periodic statistics updates, but one list-entry deletion during route replacement omitted that protection. Concurrent route replacement can therefore free an entry while mlxsw_sp_mr_stats_update accesses it. KASAN detected an eight-byte read from freed memory in the statistics-update worker; mlxsw_sp_mr_route_add was responsible for allocating and freeing the affected object.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in the Linux kernel's mlxsw Spectrum multicast-routing driver. Missing mutex protection during route replacement allows the statistics-update worker to access a freed route entry. The advisory assigns a CVSS v3 base score of 7.8, with local access and low privileges required and potentially high confidentiality, integrity, and availability impacts. The prescribed fix is to update sys-kernel/csql-kernel-6_12 and related packages to version 19216.104.113 or later.
A use-after-free vulnerability in the Linux kernel's mlxsw Spectrum multicast routing driver. During route replacement, a multicast route list entry can be deleted without acquiring the mutex used to protect concurrent statistics updates, allowing the statistics worker to access freed memory. The fix adds mutex protection around list-entry deletion. The reference assigns a CVSS v3 base score of 7.8, with local access and low privileges required, and recommends updating Echo's linux package and related packages to version 6.1.162-1 or later.
A Linux kernel use-after-free vulnerability in mlxsw spectrum_mr when updating multicast route stats.
A Linux kernel use-after-free vulnerability in mlxsw spectrum multicast route statistics handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.