cbcvebase.
CVE-2025-68207
published 2025-12-16

CVE-2025-68207: In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Synchronize Dead CT worker with unbind Cancel and wait for any Dead CT worker…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Synchronize Dead CT worker with unbind Cancel and wait for any Dead CT worker to complete before continuing with device unbinding. Else the worker will end up using resources freed by the undind operation. (cherry picked from commit 492671339114e376aaa38626d637a2751cdef263)

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.9-1 (forky)linux 6.17.9-1 (forky)
linuxlinux
linuxlinux>= 6.12.37 < 6.12.596.12.59
linuxlinux>= d2c5a5a926f43b2e42c5c955f917bad8ad6dd68c < ce6ccf8e881a919bf902174ac879f80c97669498ce6ccf8e881a919bf902174ac879f80c97669498
linuxlinux>= d2c5a5a926f43b2e42c5c955f917bad8ad6dd68c < 95af8f4fdce8349a5fe75264007f1af2aa1082ea95af8f4fdce8349a5fe75264007f1af2aa1082ea
linuxlinux>= ff6482fb458953e111a82b7c537363d9aacf04bf < 35959ab7d16b618616edf6df882a4533d2efe19335959ab7d16b618616edf6df882a4533d2efe193
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 6.12.596.12.59
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.96.17.9
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.