cbcvebase.
CVE-2025-68754
published 2026-01-05

CVE-2025-68754: In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm The clock obtained via…

PriorityP418high7.2
EPSS
0.16%
5.8th percentile
In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm The clock obtained via devm_clk_get_enabled() is automatically managed by devres and will be disabled and freed on driver detach. Manually calling clk_disable_unprepare() in error path and remove function causes double free. Remove the redundant clk_disable_unprepare() calls from the probe error path and aml_rtc_remove(), allowing the devm framework to automatically manage the clock lifecycle.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= c89ac9182ee297597f1c6971045382bae19c3f9d < 9fed02c16488050cd4e33e045506336b216d73019fed02c16488050cd4e33e045506336b216d7301
linuxlinux>= c89ac9182ee297597f1c6971045382bae19c3f9d < 2e1c79299036614ac32b251d145fad5391f4bcab2e1c79299036614ac32b251d145fad5391f4bcab
linuxlinux>= c89ac9182ee297597f1c6971045382bae19c3f9d < 384150d7a5b60c1086790a8ee07b0629f906cca2384150d7a5b60c1086790a8ee07b0629f906cca2
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.