cbcvebase.
CVE-2025-68758
published 2026-01-05

CVE-2025-68758: In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LED Backlight is a consumer of one or…

PriorityP422high7.8
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LED Backlight is a consumer of one or multiple LED class devices, but devlink is currently unable to create correct supplier-producer links when the supplier is a class device. It creates instead a link where the supplier is the parent of the expected device. One consequence is that removal order is not correctly enforced. Issues happen for example with the following sections in a device tree overlay: // An LED driver chip pca9632@62 { compatible = "nxp,pca9632"; reg = ; // ... addon_led_pwm: led-pwm@3 { reg = ; label = "addon:led:pwm"; }; }; backlight-addon { compatible = "led-backlight"; leds = ; brightness-levels = ; default-brightness-level = ; }; In this example, the devlink should be created between the backlight-addon (consumer) and the pca9632@62 (supplier). Instead it is created between the backlight-addon (consumer) and the parent of the pca9632@62, which is typically the I2C bus adapter. On removal of the above overlay, the LED driver can be removed before the backlight device, resulting in: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 ... Call trace: led_put+0xe0/0x140 devm_led_release+0x6c/0x98 Another way to reproduce the bug without any device tree overlays is unbinding the LED class device (pca9632@62) before unbinding the consumer (backlight-addon): echo 11-0062 >/sys/bus/i2c/drivers/leds-pca963x/unbind echo ...backlight-dock >/sys/bus/platform/drivers/led-backlight/unbind Fix by adding a devlink between the consuming led-backlight device and the supplying LED device, as other drivers and subsystems do as well.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 64739adf3eef063b8e2c72b7e919eac8c6480bf064739adf3eef063b8e2c72b7e919eac8c6480bf0
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < cd01a24b3e52d6777b49c917d841f125fe9eebd0cd01a24b3e52d6777b49c917d841f125fe9eebd0
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < e06df738a9ad8417f1c4c7cd6992cda320e9e7cae06df738a9ad8417f1c4c7cd6992cda320e9e7ca
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 30cbe4b642745a9488a0f0d78be43afe69d7555c30cbe4b642745a9488a0f0d78be43afe69d7555c
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 0e63ea4378489e09eb5e920c8a50c10caacf563a0e63ea4378489e09eb5e920c8a50c10caacf563a
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 60a24070392ec726ccfe6ad1ca7b0381c8d8f7c960a24070392ec726ccfe6ad1ca7b0381c8d8f7c9
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 08c9dc6b0f2c68e5e7c374ac4499e321e435d46c08c9dc6b0f2c68e5e7c374ac4499e321e435d46c
linuxlinux>= ae232e45acf9621f2c96b41ca3af006ac7552c33 < 9341d6698f4cfdfc374fb6944158d111ebe16a9d9341d6698f4cfdfc374fb6944158d111ebe16a9d
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 5.6.0 < 5.10.2485.10.248
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
ubuntulinux-aws-fips

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.