目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-68303— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.12% · P3

Affected Version Matrix 14

ベンダープロダクトVersion Rangeステータス
LinuxLinuxfdca4f16f57da76a8e68047923588a87d1c01f0a< 15d560cdf5b36c51fffec07ac2a983ab3bff4cb2affected
fdca4f16f57da76a8e68047923588a87d1c01f0a< 46e9d6f54184573dae1dcbcf6685a572ba6f4480affected
fdca4f16f57da76a8e68047923588a87d1c01f0a< 3e7442c5802146fd418ba3f68dcb9ca92b5cec83affected
fdca4f16f57da76a8e68047923588a87d1c01f0a< a21615a4ac6fecbb586d59fe2206b63501021789affected
fdca4f16f57da76a8e68047923588a87d1c01f0a< c2ee6d38996775a19bfdf20cb01a9b8698cb0baaaffected
fdca4f16f57da76a8e68047923588a87d1c01f0a< 9b9c0adbc3f8a524d291baccc9d0c04097fb4869affected
4.5affected
< 4.5unaffected
… +6 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-68303の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
platform/x86: intel: punit_ipc: fix memory corruption
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corruption This passes the address of the pointer "&punit_ipcdev" when the intent was to pass the pointer itself "punit_ipcdev" (without the ampersand). This means that the: complete(&ipcdev->cmd_complete); in intel_punit_ioc() will write to a wrong memory address corrupting it.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存损坏,可能导致系统不稳定。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux fdca4f16f57da76a8e68047923588a87d1c01f0a ~ 15d560cdf5b36c51fffec07ac2a983ab3bff4cb2 -
LinuxLinux 4.5 -

II. CVE-2025-68303の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-68303のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-68303 其他参考 (6)

Same Patch Batch · Linux · 2025-12-16 · 157 CVEs total

CVE-2025-682639.8 CRITICALksmbd: ipc: fix use-after-free in ipc_msg_send_request
CVE-2025-683019.8 CRITICALnet: atlantic: fix fragment overflow handling in RX path
CVE-2025-403509.8 CRITICALnet/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ
CVE-2025-682849.8 CRITICALlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()
CVE-2025-682859.8 CRITICALlibceph: fix potential use-after-free in have_mon_and_osd_map()
CVE-2025-681929.8 CRITICALnet: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
CVE-2025-683159.8 CRITICALf2fs: fix to detect potential corrupted nid in free_nid_list
CVE-2025-683048.8 HIGHBluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-682558.8 HIGHstaging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
CVE-2025-682568.8 HIGHstaging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
CVE-2025-682268.8 HIGHsmb: client: fix incomplete backport in cfids_invalidation_worker()
CVE-2025-403628.8 HIGHceph: fix multifs mds auth caps issue
CVE-2025-683148.8 HIGHdrm/msm: make sure last_fence is always updated
CVE-2025-682508.2 HIGHhung_task: fix warnings caused by unaligned lock pointers
CVE-2025-682947.8 HIGHio_uring/net: ensure vectored buffer node import is tied to notification
CVE-2025-681747.8 HIGHamd/amdkfd: enhance kfd process check in switch partition
CVE-2025-681757.8 HIGHmedia: nxp: imx8-isi: Fix streaming cleanup on release
CVE-2025-681797.8 HIGHs390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP
CVE-2025-681837.8 HIGHima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr
CVE-2025-682347.8 HIGHio_uring/cmd_net: fix wrong argument types for skb_queue_splice()

Showing 20 of 157 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-68303へのコメント

まだコメントはありません


コメントを残す