NVD disclosure day

Published threat advisories for December 16, 2025

CVE advisoryCRITICAL

CVE-2025-68301

Linux Kernel Network Driver Fragment Overflow Leads to Kernel Panic

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's network driver can cause a system crash when handling certain network packets. This is triggered by specially crafted traffic and affects specific network hardware, potentially leading to denial of service and impacting kernel stability.

CVE advisoryCRITICAL

CVE-2025-68285

Linux Kernel libceph Use-After-Free Vulnerability in have_mon_and_osd_map

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the Linux kernel's libceph component, specifically within the `have_mon_and_osd_map()` function. This flaw can arise from a race condition during session establishment when the client rapidly receives new network maps, potentially leading to kernel memory corruption and system i

CVE advisoryCRITICAL

CVE-2025-65319

Blue Mail Attachment Handling Weakness Bypasses Windows File Protections

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Blue Mail versions 1.140.103 and below have a vulnerability where attachments are saved without a Mark-of-the-Web tag, potentially bypassing Windows and other software protections. This could allow attackers to execute malicious files by tricking users into downloading attachments.

CVE advisoryCRITICAL

CVE-2025-65318

Canary Mail Attachment Handling Bypass Windows File Protection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Canary Mail's attachment handling can bypass Windows file protections by saving documents without a Mark-of-the-Web tag. This vulnerability could allow attackers to execute malicious files on a user's system if they interact with a specially crafted attachment. The potential for unauthorized data access or system compr

CVE advisoryCRITICAL

CVE-2025-68192

Linux Kernel qmi_wwan MAC Header Offset Initialization Failure Causes Kernel Panics.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's networking component may cause kernel panics when processing raw IP packets without proper MAC header initialization, potentially leading to system crashes. This issue can be triggered when IPsec is used over the `qmimux0` interface on ARM64 systems.

CVE advisoryCRITICAL

CVE-2025-40350

Linux Kernel mlx5e XDP Bug Causes Erroneous Packet Handling.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's network driver may cause incorrect packet data handling when XDP programs modify buffer layouts, potentially leading to kernel warnings or errors. This issue is internal to the driver's interaction with XDP programs and its relevance and exposure require confirmation.