CVE-2025-68748 — Linux vulnerability
19 documents7 sources
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateApr 6
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/panthor: Fix UAF race between device unplug and FW event processing
The function panthor_fw_unplug() will free the FW memory sections.
The problem is that there could still be pending FW events which are yet
not handled at this point. process_fw_events_work() can in this case try
to access said freed memory.
Simply call disable_work_sync() to both drain and prevent future
invocation of process_fw_events_work().
Affected Packages5 packages
▶CVEListV5linux/linuxde85488138247d034eb3241840424a54d660926b — 31db188355a49337e3e8ec98b99377e482eab22c+4