Answer in brief
CVE-2025-68371 records a Unknown severity vulnerability in scsi: smartpqi: Fix device resources accessed after device removal. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2d80f4054f7f901b8ad97358a9069616ac8524c7 <7dfa5a5516ec3c6b9b6c22ee18f0eb2df3f38ef2 || >=2d80f4054f7f901b8ad97358a9069616ac8524c7 <6d2390653d82cad0e1ba2676e536dd99678f6ef1 || >=2d80f4054f7f901b8ad97358a9069616ac8524c7 <eccc02ba1747501d92bb2049e3ce378ba372f641 || >=2d80f4054f7f901b8ad97358a9069616ac8524c7 <4e1acf1b6dd6dd0495bda139daafd7a403ae2dc1 || >=2d80f4054f7f901b8ad97358a9069616ac8524c7 <1a5c5a2f88e839af5320216a02ffb075b668596a || >=2d80f4054f7f901b8ad97358a9069616ac8524c7 <b518e86d1a70a88f6592a7c396cf1b93493d1aab | 7dfa5a5516ec3c6b9b6c22ee18f0eb2df3f38ef2, 6d2390653d82cad0e1ba2676e536dd99678f6ef1, eccc02ba1747501d92bb2049e3ce378ba372f641, 4e1acf1b6dd6dd0495bda139daafd7a403ae2dc1, 1a5c5a2f88e839af5320216a02ffb075b668596a, b518e86d1a70a88f6592a7c396cf1b93493d1aab |
| Linux/Linuxgeneric | 6.0 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Dec 24, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix device resources accessed after device removal Correct possible race conditions during device removal. Previously, a scheduled work item to reset a LUN could still execute after the device was removed, leading to use-after-free and other resource access issues. This race condition occurs because the abort handler may schedule a LUN reset concurrently with device removal via sdev_destroy(), leading to use-after-free and improper access to freed resources. - Check in the device reset handler if the device is still present in the controller's SCSI device list before running; if not, the reset is skipped. - Cancel any pending TMF work that has not started in sdev_destroy(). - Ensure device freeing in sdev_destroy() is done while holding the LUN reset mutex to avoid races with ongoing resets.
Quoted source text, attributed separately from HOL analysis.