cbcvebase.
CVE-2025-68804
published 2026-01-13

CVE-2025-68804: In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver After unbinding the driver…

PriorityP421high7.8
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver After unbinding the driver, another kthread `cros_ec_console_log_work` is still accessing the device, resulting an UAF and crash. The driver doesn't unregister the EC device in .remove() which should shutdown sub-devices synchronously. Fix it.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < 27037916db38e6b78a0242031d3b93d997b8402027037916db38e6b78a0242031d3b93d997b84020
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < e1da6e399df976dd04c7c73ec008bc81da368a95e1da6e399df976dd04c7c73ec008bc81da368a95
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < 8dc1f5a85286290dbf04dd5951d020570f49779b8dc1f5a85286290dbf04dd5951d020570f49779b
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < 393b8f9bedc7806acb9c47cefdbdb223b4b6164b393b8f9bedc7806acb9c47cefdbdb223b4b6164b
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < 4701493ba37654b3c38b526f6591cf0b02aa172f4701493ba37654b3c38b526f6591cf0b02aa172f
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < 24a2062257bbdfc831de5ed21c27b04b5bdf243724a2062257bbdfc831de5ed21c27b04b5bdf2437
linuxlinux>= 26a14267aff218c60b89007fdb44ca392ba6122c < 944edca81e7aea15f83cf9a13a6ab67f711e8abd944edca81e7aea15f83cf9a13a6ab67f711e8abd
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 5.3.0 < 5.10.2485.10.248
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.