Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-68787

Published Jan 13, 2026

Overview

CVE-2025-68787 is a known-severity vulnerability. It was published on January 13, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

netrom: Fix memory leak in nr_sendmsg()

syzbot reported a memory leak [1].

When function sock_alloc_send_skb() return NULL in nr_output(), the

original skb is not freed, which was allocated in nr_sendmsg(). Fix this

by freeing it before return.

[1]

BUG: memory leak

unreferenced object 0xffff888129f35500 (size 240):

comm "syz.0.17", pid 6119, jiffies 4294944652

hex dump (first 32 bytes):

00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................

00 00 00 00 00 00 00 00 00 10 52 28 81 88 ff ff ..........R(....

backtrace (crc 1456a3e4):

kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]

slab_post_alloc_hook mm/slub.c:4983 [inline]

slab_alloc_node mm/slub.c:5288 [inline]

kmem_cache_alloc_node_noprof+0x36f/0x5e0 mm/slub.c:5340

__alloc_skb+0x203/0x240 net/core/skbuff.c:660

alloc_skb include/linux/skbuff.h:1383 [inline]

alloc_skb_with_frags+0x69/0x3f0 net/core/s

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2025-68787?

CVE-2025-68787 is a known-severity vulnerability. It was published on January 13, 2026.

How severe is CVE-2025-68787?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2025-68787?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-68787?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-68787 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.