cbcvebase.
CVE-2025-68238
published 2025-12-16

CVE-2025-68238: In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: cadence: fix DMA device NULL pointer dereference The DMA device pointer…

PriorityP422high7.8
EPSS
0.17%
6.7th percentile
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: cadence: fix DMA device NULL pointer dereference The DMA device pointer `dma_dev` was being dereferenced before ensuring that `cdns_ctrl->dmac` is properly initialized. Move the assignment of `dma_dev` after successfully acquiring the DMA channel to ensure the pointer is valid before use.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 099a316518508be7c57de4134ef919b2dea948ce < 9c58c64ec41290c12490ca7e1df45013fbbb41fd9c58c64ec41290c12490ca7e1df45013fbbb41fd
linuxlinux>= 0cae7c285f4771a9927ef592899234d307aea5d4 < 2178b0255eae108bb10e5e99658b28641bc06f432178b0255eae108bb10e5e99658b28641bc06f43
linuxlinux>= 0ce5416863965ddd86e066484a306867cf1e01a8 < 0c635241a62f2f5da1b48bfffae226d1f86a76ef0c635241a62f2f5da1b48bfffae226d1f86a76ef
linuxlinux>= 5.10.235 < 5.10.2475.10.247
linuxlinux>= 5.15.179 < 5.15.1975.15.197
linuxlinux>= 6.1.130 < 6.1.1596.1.159
linuxlinux>= 6.12.17 < 6.12.606.12.60
linuxlinux>= 6.13.5 < 6.146.14
linuxlinux>= 6.6.80 < 6.6.1186.6.118
linuxlinux>= ad9393467fbd788ac2b8a01e492e45ab1b68a1b1 < b146e0b085d9d6bfe838e0a15481cba7d093c67fb146e0b085d9d6bfe838e0a15481cba7d093c67f
linuxlinux>= d76d22b5096c5b05208fd982b153b3f182350b19 < 0c2a43cb43786011b48eeab6093db14888258c6b0c2a43cb43786011b48eeab6093db14888258c6b
linuxlinux>= d76d22b5096c5b05208fd982b153b3f182350b19 < 5c56bf214af85ca042bf97f8584aab21510358405c56bf214af85ca042bf97f8584aab2151035840
linuxlinux>= e630d32162a8aab92d4aaebae0a8d93039257593 < e282a4fdf3c6ee842a720010a8b5f7d77bedd126e282a4fdf3c6ee842a720010a8b5f7d77bedd126
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 5.10.2475.10.247
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.