-

CVE-2025-68303

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: intel: punit_ipc: fix memory corruption

This passes the address of the pointer "&punit_ipcdev" when the intent
was to pass the pointer itself "punit_ipcdev" (without the ampersand).
This means that the:

	complete(&ipcdev->cmd_complete);

in intel_punit_ioc() will write to a wrong memory address corrupting it.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 15d560cdf5b36c51fffec07ac2a983ab3bff4cb2
Version fdca4f16f57da76a8e68047923588a87d1c01f0a
Status affected
Version < 46e9d6f54184573dae1dcbcf6685a572ba6f4480
Version fdca4f16f57da76a8e68047923588a87d1c01f0a
Status affected
Version < 3e7442c5802146fd418ba3f68dcb9ca92b5cec83
Version fdca4f16f57da76a8e68047923588a87d1c01f0a
Status affected
Version < a21615a4ac6fecbb586d59fe2206b63501021789
Version fdca4f16f57da76a8e68047923588a87d1c01f0a
Status affected
Version < c2ee6d38996775a19bfdf20cb01a9b8698cb0baa
Version fdca4f16f57da76a8e68047923588a87d1c01f0a
Status affected
Version < 9b9c0adbc3f8a524d291baccc9d0c04097fb4869
Version fdca4f16f57da76a8e68047923588a87d1c01f0a
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.5
Status affected
Version < 4.5
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.197
Status unaffected
Version <= 6.1.*
Version 6.1.159
Status unaffected
Version <= 6.6.*
Version 6.6.119
Status unaffected
Version <= 6.12.*
Version 6.12.61
Status unaffected
Version <= 6.17.*
Version 6.17.11
Status unaffected
Version <= *
Version 6.18
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.