cbcvebase.
CVE-2025-68167
published 2025-12-16

CVE-2025-68167: In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix invalid pointer access in debugfs If the memory allocation in…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.2th percentile
In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix invalid pointer access in debugfs If the memory allocation in gpiolib_seq_start() fails, the s->private field remains uninitialized and is later dereferenced without checking in gpiolib_seq_stop(). Initialize s->private to NULL before calling kzalloc() and check it before dereferencing it.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= e348544f7994d252427ed3ae637c7081cbb90f66 < 70180a6031056096c93ed2f47c41803268bdd91c70180a6031056096c93ed2f47c41803268bdd91c
linuxlinux>= e348544f7994d252427ed3ae637c7081cbb90f66 < 3c91c8f424d3e44c8645ab765a38773e58afb07d3c91c8f424d3e44c8645ab765a38773e58afb07d
linuxlinux>= e348544f7994d252427ed3ae637c7081cbb90f66 < 2f6115ad8864cf3f48598f26c74c7c8e5c3919192f6115ad8864cf3f48598f26c74c7c8e5c391919
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.9.0 < 6.12.586.12.58
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.