CVE-2025-68741Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix improper freeing of purex item In qla2xxx_process_purls_iocb(), an item is allocated via qla27xx_copy_multiple_pkt(), which internally calls qla24xx_alloc_purex_item(). The qla24xx_alloc_purex_item() function may return a pre-allocated item from a per-adapter pool for small allocations, instead of dynamically allocating memory with kzalloc(). An error handling path in qla2xxx_process_purls_iocb() incorrectly uses kfree() to release the item. If the item was from the pre-allocated pool, calling kfree() on it is a bug that can lead to memory corruption. Fix this by using the correct deallocation function, qla24xx_free_purex_item(), which properly handles both dynamically allocated and pre-allocated items.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-26: 2Patch / Workaround · 2026-04-26: 204-26
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    The kernel-rt CVEs (CVE-2025-68741, CVE-2026-23191) from April 2026 are just examples. Here’s how to check, patch, and mitigate – plus the book that turns you from a patcher into a vulnerability hunter. - > http://tinyurl.com/56sjcasz #AlmaLinux #Security https://t.co/QFwfXxlvIa

    Post summary

    The tweet lists kernel‑rt CVE IDs and indicates readers can check, patch, and mitigate them, but lacks technical or exploit specifics.

    10000671
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Stop chasing CVEs. One script fixes CVE-2025-68741. But one book teaches you to find the next 100 zero-days before they’re disclosed. Master it → “Practical Binary Analysis” -> http://amzn.to/4cM9DwO I earn a comission with you make a purchase.

    Post summary

    The post announces that a script is available to patch CVE‑2025‑68741, with no mention of exploitation or vulnerability details.

    00000691
    1.5K followersView on X

Explore more