cbcvebase.
CVE-2025-68335
published 2025-12-22

CVE-2025-68335: In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel() Syzbot identified an issue [1] in…

PriorityP422high7.8
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel() Syzbot identified an issue [1] in pcl818_ai_cancel(), which stems from the fact that in case of early device detach via pcl818_detach(), subdevice dev->read_subdev may not have initialized its pointer to &struct comedi_async as intended. Thus, any such dereferencing of &s->async->cmd will lead to general protection fault and kernel crash. Mitigate this problem by removing a call to pcl818_ai_cancel() from pcl818_detach() altogether. This way, if the subdevice setups its support for async commands, everything async-related will be handled via subdevice's own ->cancel() function in comedi_device_detach_locked() even before pcl818_detach(). If no support for asynchronous commands is provided, there is no need to cancel anything either. [1] Syzbot crash: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000005: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] CPU: 1 UID: 0 PID: 6050 Comm: syz.0.18 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 RIP: 0010:pcl818_ai_cancel+0x69/0x3f0 drivers/comedi/drivers/pcl818.c:762 ... Call Trace: pcl818_detach+0x66/0xd0 drivers/comedi/drivers/pcl818.c:1115 comedi_device_detach_locked+0x178/0x750 drivers/comedi/drivers.c:207 do_devconfig_ioctl drivers/comedi/comedi_fops.c:848 [inline] comedi_unlocked_ioctl+0xcde/0x1020 drivers/comedi/comedi_fops.c:2178 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] ...

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < b2a5b172dc05be6c4f2c5542c1bbc6b14d60ff16b2a5b172dc05be6c4f2c5542c1bbc6b14d60ff16
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < 935ad4b3c325c24fff2c702da403283025ffc722935ad4b3c325c24fff2c702da403283025ffc722
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < 88d99ca5adbd01ff088f5fb2ddeba5755e085e5288d99ca5adbd01ff088f5fb2ddeba5755e085e52
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < 5caa40e7c6a43e08e3574f990865127705c228615caa40e7c6a43e08e3574f990865127705c22861
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < d948c53dec36dafe182631457597c49c1f1df5ead948c53dec36dafe182631457597c49c1f1df5ea
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < 877adccfacb32687b90714a27cfb09f444fdfa16877adccfacb32687b90714a27cfb09f444fdfa16
linuxlinux>= 00aba6e7b5653a6607238ecdab7172318059d984 < a51f025b5038abd3d22eed2ede4cd46793d89565a51f025b5038abd3d22eed2ede4cd46793d89565
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.12-16.17.12-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 3.15.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.126.17.12
linuxlinux_kernel>= 6.18.0 < 6.18.16.18.1
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.626.12.62
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.