cbcvebase.
CVE-2025-68766
published 2026-01-05

CVE-2025-68766: In the Linux kernel, the following vulnerability has been resolved: irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc() If…

PriorityP421high7.2
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc() If irq_domain_translate_twocell() sets "hwirq" to >= MCHP_EIC_NIRQ (2) then it results in an out of bounds access. The code checks for invalid values, but doesn't set the error code. Return -EINVAL in that case, instead of returning success.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 00fa3461c86dd289b441d4d5a6bb236064bd207b < 324c60a67c4b9668497940f667db14d216cc7b1b324c60a67c4b9668497940f667db14d216cc7b1b
linuxlinux>= 00fa3461c86dd289b441d4d5a6bb236064bd207b < c21c606ad398eeb86a0f3aaff9ba4f2665e286c6c21c606ad398eeb86a0f3aaff9ba4f2665e286c6
linuxlinux>= 00fa3461c86dd289b441d4d5a6bb236064bd207b < 3873afcb57614c1aaa5b6715554d6d1c22cac95a3873afcb57614c1aaa5b6715554d6d1c22cac95a
linuxlinux>= 00fa3461c86dd289b441d4d5a6bb236064bd207b < 09efe7cfbf919c4d763bc425473fcfee0dc9835609efe7cfbf919c4d763bc425473fcfee0dc98356
linuxlinux>= 00fa3461c86dd289b441d4d5a6bb236064bd207b < efd65e2e2fd96f7aaa5cb07d79bbbfcfc80aa552efd65e2e2fd96f7aaa5cb07d79bbbfcfc80aa552
linuxlinux>= 00fa3461c86dd289b441d4d5a6bb236064bd207b < 7dbc0d40d8347bd9de55c904f59ea44bcc8dedb77dbc0d40d8347bd9de55c904f59ea44bcc8dedb7
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.