CVE-2025-68822 — Expired Pointer Dereference in Linux
Severity
6.4MEDIUM
No vectorEPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateApr 17
Description
In the Linux kernel, the following vulnerability has been resolved:
Input: alps - fix use-after-free bugs caused by dev3_register_work
The dev3_register_work delayed work item is initialized within
alps_reconnect() and scheduled upon receipt of the first bare
PS/2 packet from an external PS/2 device connected to the ALPS
touchpad. During device detachment, the original implementation
calls flush_workqueue() in psmouse_disconnect() to ensure
completion of dev3_register_work. However, the flush_…
Affected Packages7 packages
▶CVEListV5linux/linux04aae283ba6a8cd4851d937bf9c6d6ef0361d794 — ed8c61b89be0c45f029228b2913d5cf7b5cda1a7+3
🔴Vulnerability Details
3OSV▶
CVE-2025-68822: In the Linux kernel, the following vulnerability has been resolved: Input: alps - fix use-after-free bugs caused by dev3_register_work The dev3_regist↗2026-01-13
GHSA▶
GHSA-5w2m-pcx5-5834: In the Linux kernel, the following vulnerability has been resolved:
Input: alps - fix use-after-free bugs caused by dev3_register_work
The dev3_regi↗2026-01-13
📋Vendor Advisories
5Debian▶
CVE-2025-68822: linux - In the Linux kernel, the following vulnerability has been resolved: Input: alps...↗2025