cbcvebase.
CVE-2025-68309
published 2025-12-16

CVE-2025-68309: In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Fix NULL pointer access by aer_info The kzalloc(GFP_KERNEL) may return NULL, so…

PriorityP419medium5.5
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Fix NULL pointer access by aer_info The kzalloc(GFP_KERNEL) may return NULL, so all accesses to aer_info->xxx will result in kernel panic. Fix it.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= a57f2bfb4a5863f83087867c0e671f2418212d23 < 6618243bcc3f60825f761a41ed65fef9fe97eb256618243bcc3f60825f761a41ed65fef9fe97eb25
linuxlinux>= a57f2bfb4a5863f83087867c0e671f2418212d23 < 0a27bdb14b028fed30a10cec2f945c38cb5ca4fa0a27bdb14b028fed30a10cec2f945c38cb5ca4fa
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.16.0 < 6.17.86.17.8
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.