cbcvebase.
CVE-2025-68303
published 2025-12-16

CVE-2025-68303: In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corruption This passes the address of the…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corruption This passes the address of the pointer "&punit_ipcdev" when the intent was to pass the pointer itself "punit_ipcdev" (without the ampersand). This means that the: complete(&ipcdev->cmd_complete); in intel_punit_ioc() will write to a wrong memory address corrupting it.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= fdca4f16f57da76a8e68047923588a87d1c01f0a < 15d560cdf5b36c51fffec07ac2a983ab3bff4cb215d560cdf5b36c51fffec07ac2a983ab3bff4cb2
linuxlinux>= fdca4f16f57da76a8e68047923588a87d1c01f0a < 46e9d6f54184573dae1dcbcf6685a572ba6f448046e9d6f54184573dae1dcbcf6685a572ba6f4480
linuxlinux>= fdca4f16f57da76a8e68047923588a87d1c01f0a < 3e7442c5802146fd418ba3f68dcb9ca92b5cec833e7442c5802146fd418ba3f68dcb9ca92b5cec83
linuxlinux>= fdca4f16f57da76a8e68047923588a87d1c01f0a < a21615a4ac6fecbb586d59fe2206b63501021789a21615a4ac6fecbb586d59fe2206b63501021789
linuxlinux>= fdca4f16f57da76a8e68047923588a87d1c01f0a < c2ee6d38996775a19bfdf20cb01a9b8698cb0baac2ee6d38996775a19bfdf20cb01a9b8698cb0baa
linuxlinux>= fdca4f16f57da76a8e68047923588a87d1c01f0a < 9b9c0adbc3f8a524d291baccc9d0c04097fb48699b9c0adbc3f8a524d291baccc9d0c04097fb4869
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.5.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.2.0 < 6.6.1196.6.119
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-azure-5.15
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.