cbcvebase.
CVE-2025-68732
published 2025-12-24

CVE-2025-68732: In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix race in syncpt alloc/free Fix race condition between host1x_syncpt_alloc()…

PriorityP419high7.8
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix race in syncpt alloc/free Fix race condition between host1x_syncpt_alloc() and host1x_syncpt_put() by using kref_put_mutex() instead of kref_put() + manual mutex locking. This ensures no thread can acquire the syncpt_mutex after the refcount drops to zero but before syncpt_release acquires it. This prevents races where syncpoints could be allocated while still being cleaned up from a previous release. Remove explicit mutex locking in syncpt_release as kref_put_mutex() handles this atomically.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < ca9388fba50dac2eb71c13702b7022a801bef90eca9388fba50dac2eb71c13702b7022a801bef90e
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < 4aeaece518fa4436af93d1d8b786200d9656ff4b4aeaece518fa4436af93d1d8b786200d9656ff4b
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < 6245cce711e2cdb2cc75c0bb8632952e36f8c9726245cce711e2cdb2cc75c0bb8632952e36f8c972
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < 4e6e07ce0197aecfb6c4a62862acc93b3efedeb74e6e07ce0197aecfb6c4a62862acc93b3efedeb7
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < d138f73ffb0c57ded473c577719e6e551b7b1f27d138f73ffb0c57ded473c577719e6e551b7b1f27
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < 79197c6007f2afbfd7bcf5b9b80ccabf8483d77479197c6007f2afbfd7bcf5b9b80ccabf8483d774
linuxlinux>= f5ba33fb9690566c382624637125827b5512e766 < c7d393267c497502fa737607f435f05dfe6e3d9bc7d393267c497502fa737607f435f05dfe6e3d9b
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.13.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
ubuntulinux-aws-fips

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.