CVE-2025-68775: net/handshake: duplicate handshake cancellations leak socket
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: duplicate handshake cancellations leak socket
When a handshake request is cancelled it is removed from the handshakenet->hnrequests list, but it is still present in the handshakerhashtbl until it is destroyed.
If a second cancellation request arrives for the same handshake request, then removepending() will return false... and assuming HANDSHAKEFREQCOMPLETED isn't set in req->hrflags, we'll continue processing through the outtrue label, where we put another reference on the sock and a refcount underflow occurs.
This can happen for example if a handshake times out - particularly if the SUNRPC client sends the AUTHTLS probe to the server but doesn't follow it up with the ClientHello due to a problem with tlshd. When the timeout is hit on the server, the server will send a FIN, which triggers a cancellation request via xsresettransport(). When the timeout is hit on the client, another cancellation request happens via xstlshandshakesync().
Add a testandsetbit(HANDSHAKEFREQCOMPLETED) in the pending cancel path so duplicate cancels can be detected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68775?
CVE-2025-68775 has a medium severity rating due to potential information leakage from duplicate handshake cancellations.
What systems are affected by CVE-2025-68775?
CVE-2025-68775 affects the Linux kernel networking subsystem.
How do I fix CVE-2025-68775?
To fix CVE-2025-68775, update your Linux kernel to the latest stable version that includes the patch.
What impact does CVE-2025-68775 have on system security?
CVE-2025-68775 may allow attackers to leak sensitive information through improper handling of handshake cancellations.
When was CVE-2025-68775 discovered?
CVE-2025-68775 was identified and reported in 2025.