cbcvebase.
CVE-2025-68797
published 2026-01-13

CVE-2025-68797: In the Linux kernel, the following vulnerability has been resolved: char: applicom: fix NULL pointer dereference in ac_ioctl Discovered by Atuin - Automated…

PriorityP423high7.8
EPSS
0.17%
7.0th percentile
In the Linux kernel, the following vulnerability has been resolved: char: applicom: fix NULL pointer dereference in ac_ioctl Discovered by Atuin - Automated Vulnerability Discovery Engine. In ac_ioctl, the validation of IndexCard and the check for a valid RamIO pointer are skipped when cmd is 6. However, the function unconditionally executes readb(apbs[IndexCard].RamIO + VERS) at the end. If cmd is 6, IndexCard may reference a board that does not exist (where RamIO is NULL), leading to a NULL pointer dereference. Fix this by skipping the readb access when cmd is 6, as this command is a global information query and does not target a specific board context.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5a6240804fb7bbd4f5f6e706955248a6f4c1abbc5a6240804fb7bbd4f5f6e706955248a6f4c1abbc
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d1b0452280029d05a98c75631131ee61c0b0d084d1b0452280029d05a98c75631131ee61c0b0d084
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0b8b353e09888bccee405e0dd6feafb60360f4780b8b353e09888bccee405e0dd6feafb60360f478
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d285517429a75423789e6408653e57b6fdfc8e54d285517429a75423789e6408653e57b6fdfc8e54
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 74883565c621eec6cd2e35fe6d27454cf2810c2374883565c621eec6cd2e35fe6d27454cf2810c23
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f83e3e9f89181b42f6076a115d767a7552c4a39ef83e3e9f89181b42f6076a115d767a7552c4a39e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 82d12088c297fa1cef670e1718b3d24f414c23f782d12088c297fa1cef670e1718b3d24f414c23f7
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.12 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.