cbcvebase.
CVE-2025-68367
published 2025-12-24

CVE-2025-68367: In the Linux kernel, the following vulnerability has been resolved: macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse The following warning…

PriorityP423high7.8
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse The following warning appears when running syzkaller, and this issue also exists in the mainline code. ------------[ cut here ]------------ list_add double add: new=ffffffffa57eee28, prev=ffffffffa57eee28, next=ffffffffa5e63100. WARNING: CPU: 0 PID: 1491 at lib/list_debug.c:35 __list_add_valid_or_report+0xf7/0x130 Modules linked in: CPU: 0 PID: 1491 Comm: syz.1.28 Not tainted 6.6.0+ #3 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:__list_add_valid_or_report+0xf7/0x130 RSP: 0018:ff1100010dfb7b78 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffffffffa57eee18 RCX: ffffffff97fc9817 RDX: 0000000000040000 RSI: ffa0000002383000 RDI: 0000000000000001 RBP: ffffffffa57eee28 R08: 0000000000000001 R09: ffe21c0021bf6f2c R10: 0000000000000001 R11: 6464615f7473696c R12: ffffffffa5e63100 R13: ffffffffa57eee28 R14: ffffffffa57eee28 R15: ff1100010dfb7d48 FS: 00007fb14398b640(0000) GS:ff11000119600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 000000010d096005 CR4: 0000000000773ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 80000000 Call Trace: input_register_handler+0xb3/0x210 mac_hid_start_emulation+0x1c5/0x290 mac_hid_toggle_emumouse+0x20a/0x240 proc_sys_call_handler+0x4c2/0x6e0 new_sync_write+0x1b1/0x2d0 vfs_write+0x709/0x950 ksys_write+0x12a/0x250 do_syscall_64+0x5a/0x110 entry_SYSCALL_64_after_hwframe+0x78/0xe2 The WARNING occurs when two processes concurrently write to the mac-hid emulation sysctl, causing a race condition in mac_hid_toggle_emumouse(). Both processes read old_val=0, then both try to register the input handler, leading to a double list_add of the same handler. CPU0 CPU1 -------------------------

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < d5f1d40fd342b589420de7508b4c748fcf28122ed5f1d40fd342b589420de7508b4c748fcf28122e
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 14c209835e47a87e6da94bb9401e570dcc14f31f14c209835e47a87e6da94bb9401e570dcc14f31f
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 583d36523f56d8e9ddfa0bec20743a6faefc9b74583d36523f56d8e9ddfa0bec20743a6faefc9b74
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 61abf8c3162d155b4fd0fb251f08557093363a0a61abf8c3162d155b4fd0fb251f08557093363a0a
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 230621ffdb361d15cd3ef92d8b4fa8d314f4fad4230621ffdb361d15cd3ef92d8b4fa8d314f4fad4
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 388391dd1cc567fcf0b372b63d414c119d23e911388391dd1cc567fcf0b372b63d414c119d23e911
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 48a7d427eb65922b3f17fbe00e2bbc7cb9eac38148a7d427eb65922b3f17fbe00e2bbc7cb9eac381
linuxlinux>= 99b089c3c38a83ebaeb1cc4584ddcde841626467 < 1e4b207ffe54cf33a4b7a2912c4110f89c73bf3f1e4b207ffe54cf33a4b7a2912c4110f89c73bf3f
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 2.6.34 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.