cbcvebase.
CVE-2025-68755
published 2026-01-05

CVE-2025-68755: In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I2C driver has been completely broken for…

PriorityP421high7.2
EPSS
0.16%
5.9th percentile
In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I2C driver has been completely broken for five years without anyone noticing so remove the driver from staging. Specifically, commit 723de0f9171e ("staging: most: remove device from interface structure") started requiring drivers to set the interface device pointer before registration, but the I2C driver was never updated which results in a NULL pointer dereference if anyone ever tries to probe it.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 6cbba922934805f86eece6ba7010b7201962695d6cbba922934805f86eece6ba7010b7201962695d
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 6059a66dba7f26b21852831432e17075f1a1c7836059a66dba7f26b21852831432e17075f1a1c783
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < e463548fd80e779efea1cb2d3049b8a7231e6925e463548fd80e779efea1cb2d3049b8a7231e6925
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 495df2da6944477d282d5cc0c13174d06e25b310495df2da6944477d282d5cc0c13174d06e25b310
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.6.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.7.0 < 6.17.136.17.13
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-hwe-6.8
ubuntulinux-ibm-6.8
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-nvidia-lowlatency
ubuntulinux-nvidia-tegra
ubuntulinux-oracle

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.