-

CVE-2025-68789

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (ibmpex) fix use-after-free in high/low store

The ibmpex_high_low_store() function retrieves driver data using
dev_get_drvdata() and uses it without validation. This creates a race
condition where the sysfs callback can be invoked after the data
structure is freed, leading to use-after-free.

Fix by adding a NULL check after dev_get_drvdata(), and reordering
operations in the deletion path to prevent TOCTOU.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 3ce9b7ae9d4d148672b35147aaf7987a4f82bb94
Version 57c7c3a0fdea95eddcaeba31e7ca7dfc917682ab
Status affected
Version < 533ead425f8109b02fecc7e72d612b8898ec347a
Version 57c7c3a0fdea95eddcaeba31e7ca7dfc917682ab
Status affected
Version < fa37adcf1d564ef58b9dfb01b6c36d35c5294bad
Version 57c7c3a0fdea95eddcaeba31e7ca7dfc917682ab
Status affected
Version < 68d62e5bebbd118b763e8bb210d5cf2198ef450c
Version 57c7c3a0fdea95eddcaeba31e7ca7dfc917682ab
Status affected
Version < 5aa2139201667c1f644601e4529c4acd6bf8db5a
Version 57c7c3a0fdea95eddcaeba31e7ca7dfc917682ab
Status affected
Version < 6946c726c3f4c36f0f049e6f97e88c510b15f65d
Version 57c7c3a0fdea95eddcaeba31e7ca7dfc917682ab
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.24
Status affected
Version < 2.6.24
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.248
Status unaffected
Version <= 6.1.*
Version 6.1.160
Status unaffected
Version <= 6.6.*
Version 6.6.120
Status unaffected
Version <= 6.12.*
Version 6.12.64
Status unaffected
Version <= 6.18.*
Version 6.18.3
Status unaffected
Version <= *
Version 6.19-rc2
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.