CVE-2025-68748
Published: Dec 24, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF race between device unplug and FW event processing The function panthor_fw_unplug() will free the FW memory sections. The problem is that there could still be pending FW events which are yet not handled at this point. process_fw_events_work() can in this case try to access said freed memory. Simply call disable_work_sync() to both drain and prevent future invocation of process_fw_events_work().
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected de85488138247d034eb3241840424a54d660926b - < 31db188355a49337e3e8ec98b99377e482eab22caffected de85488138247d034eb3241840424a54d660926b - < 5e3ff56d4cb591daea70786d07dc21d06dc34108affected de85488138247d034eb3241840424a54d660926b - < 6c1da9ae2c123a9ffda5375e64cc81f9ed3cc04aaffected de85488138247d034eb3241840424a54d660926b - < 7051f6ba968fa69918d72cc26de4d6cf7ea05b90 |
Linux | Linux | affected 6.10unaffected 0 - < 6.10unaffected 6.12.63 - <= 6.12.*unaffected 6.17.13 - <= 6.17.*unaffected 6.18.2 - <= 6.18.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now