cbcvebase.
CVE-2025-68316
published 2025-12-16

CVE-2025-68316: In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix invalid probe error return value After DME Link Startup, the error…

PriorityP419medium5.3
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix invalid probe error return value After DME Link Startup, the error return value is set to the MIPI UniPro GenericErrorCode which can be 0 (SUCCESS) or 1 (FAILURE). Upon failure during driver probe, the error code 1 is propagated back to the driver probe function which must return a negative value to indicate an error, but 1 is not negative, so the probe is considered to be successful even though it failed. Subsequently, removing the driver results in an oops because it is not in a valid state. This happens because none of the callers of ufshcd_init() expect a non-negative error code. Fix the return value and documentation to match actual usage.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 69f5eb78d4b0cc978fe83dd2bfea1b67547290bf < df96dbe1af7f6591c09f862f1226d3619b07e1b6df96dbe1af7f6591c09f862f1226d3619b07e1b6
linuxlinux>= 69f5eb78d4b0cc978fe83dd2bfea1b67547290bf < a2b32bc1d9e359a9f90d0de6af16699facb10935a2b32bc1d9e359a9f90d0de6af16699facb10935
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
ubuntulinux-aws
ubuntulinux-oracle
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.