CVE-2025-68173
In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix softlockup in ftrace_module_enable A soft lockup was observed when loading amdgpu module. If a module has a lot of tracable functions, multiple calls to kallsyms_lookup can spend too much time in RCU critical section and with disabled preemption, causing kernel panic. This is the same issue that was fixed in commit d0b24b4e91fc ("ftrace: Prevent RCU stall on PREEMPT_VOLUNTARY kernels") and commit 42ea22e754ba ("ftrace: Add cond_resched() to ftrace_graph_set_hash()"). Fix it the same way by adding cond_resched() in ftrace_module_enable.
Affected versions
Linux kernel versions
4.5
and later are affected. Fixed in
6.1.159,
6.6.117,
6.12.58,
6.17.8,
6.18
and their respective stable series.
References
The following references provide additional information about CVE-2025-68173 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/4099b98203d6b33d990586542fa5beee408032a3
-
PatchKernel patch commithttps://git.kernel.org/stable/c/40c8ee40e48a2c82c762539952ed8fc0571db5bf
-
PatchKernel patch commithttps://git.kernel.org/stable/c/7e3c96010ade29bb340a5bdce8675f50c7f59001
Frequently asked questions
-
What is CVE-2025-68173?
CVE-2025-68173 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.5 onward and has been patched in 6.1.159, 6.6.117, 6.12.58 and others. CVE-2025-68173 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2025-68173?
Yes — CVE-2025-68173 has been patched. Fixed versions include 6.1.159, 6.6.117, 6.12.58 and others. If you are running Linux kernel 4.5 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2025-68173 actively exploited?
No — CVE-2025-68173 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.