cbcvebase.
CVE-2025-68777
published 2026-01-13

CVE-2025-68777: In the Linux kernel, the following vulnerability has been resolved: Input: ti_am335x_tsc - fix off-by-one error in wire_order validation The current validation…

PriorityP423high7.8
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Input: ti_am335x_tsc - fix off-by-one error in wire_order validation The current validation 'wire_order[i] > ARRAY_SIZE(config_pins)' allows wire_order[i] to equal ARRAY_SIZE(config_pins), which causes out-of-bounds access when used as index in 'config_pins[wire_order[i]]'. Since config_pins has 4 elements (indices 0-3), the valid range for wire_order should be 0-3. Fix the off-by-one error by using >= instead of > in the validation check.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < a7ff2360431561b56f559d3a628d1f096048d178a7ff2360431561b56f559d3a628d1f096048d178
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < 136abe173a3cc2951d70c6e51fe7abdbadbb204b136abe173a3cc2951d70c6e51fe7abdbadbb204b
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < 08c0b561823a7026364efb38ed7f4a3af48ccfcd08c0b561823a7026364efb38ed7f4a3af48ccfcd
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < bf95ec55805828c4f2b5241fb6b0c12388548570bf95ec55805828c4f2b5241fb6b0c12388548570
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < 84e4d3543168912549271b34261f5e0f94952d6e84e4d3543168912549271b34261f5e0f94952d6e
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < 40e3042de43ffa0017a8460ff9b4cad7b8c7cb9640e3042de43ffa0017a8460ff9b4cad7b8c7cb96
linuxlinux>= bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439 < 248d3a73a0167dce15ba100477c3e778c4787178248d3a73a0167dce15ba100477c3e778c4787178
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 3.11.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.