CVE-2025-68222 — Use of Uninitialized Resource in Linux
Severity
7.2HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc
s32_pinctrl_desc is allocated with devm_kmalloc(), but not all of its
fields are initialized. Notably, num_custom_params is used in
pinconf_generic_parse_dt_config(), resulting in intermittent allocation
errors, such as the following splat when probing i2c-imx:
WARNING: CPU: 0 PID: 176 at mm/page_alloc.c:4795 __alloc_pages_noprof+0x290/0x300
[...]
Hardware name: NXP…
Affected Packages6 packages
▶CVEListV5linux/linuxfd84aaa8173d3ff86f8df2009921336a1ea53a8a — 3b90bd8aaeb21b513ecc4ed03299e80ece44a333+4