cbcvebase.
CVE-2025-68176
published 2025-12-16

CVE-2025-68176: In the Linux kernel, the following vulnerability has been resolved: PCI: cadence: Check for the existence of cdns_pcie::ops before using it cdns_pcie::ops…

PriorityP420high7.8
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI: cadence: Check for the existence of cdns_pcie::ops before using it cdns_pcie::ops might not be populated by all the Cadence glue drivers. This is going to be true for the upcoming Sophgo platform which doesn't set the ops. Hence, add a check to prevent NULL pointer dereference. [mani: reworded subject and description]

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < d5dbe92ac8a4ca6226093241f95f9cb1b0d2e0e1d5dbe92ac8a4ca6226093241f95f9cb1b0d2e0e1
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < eb3d29ca0820fa3d7cccad47d2da56c9ab5469edeb3d29ca0820fa3d7cccad47d2da56c9ab5469ed
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < 0d0bb756f002810d249caee51f3f1c309f3cdab50d0bb756f002810d249caee51f3f1c309f3cdab5
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < 1810b2fd7375de88a74976dcd402b29088e479ed1810b2fd7375de88a74976dcd402b29088e479ed
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < 953eb3796ef06b8ea3bf6bdde14156255bc75866953eb3796ef06b8ea3bf6bdde14156255bc75866
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < 363448d069e29685ca37a118065121e486387af3363448d069e29685ca37a118065121e486387af3
linuxlinux>= 40d957e6f9eb3a8a585007b8b730340c829afbdb < 49a6c160ad4812476f8ae1a8f4ed6d15adfa6c0949a6c160ad4812476f8ae1a8f4ed6d15adfa6c09
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.9.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
ubuntulinux-aws
ubuntulinux-azure-5.15

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.