目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-68758— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.17% · P6

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinuxae232e45acf9621f2c96b41ca3af006ac7552c33< 64739adf3eef063b8e2c72b7e919eac8c6480bf0affected
ae232e45acf9621f2c96b41ca3af006ac7552c33< cd01a24b3e52d6777b49c917d841f125fe9eebd0affected
ae232e45acf9621f2c96b41ca3af006ac7552c33< e06df738a9ad8417f1c4c7cd6992cda320e9e7caaffected
ae232e45acf9621f2c96b41ca3af006ac7552c33< 30cbe4b642745a9488a0f0d78be43afe69d7555caffected
ae232e45acf9621f2c96b41ca3af006ac7552c33< 0e63ea4378489e09eb5e920c8a50c10caacf563aaffected
ae232e45acf9621f2c96b41ca3af006ac7552c33< 60a24070392ec726ccfe6ad1ca7b0381c8d8f7c9affected
ae232e45acf9621f2c96b41ca3af006ac7552c33< 08c9dc6b0f2c68e5e7c374ac4499e321e435d46caffected
ae232e45acf9621f2c96b41ca3af006ac7552c33< 9341d6698f4cfdfc374fb6944158d111ebe16a9daffected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-68758 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
backlight: led-bl: Add devlink to supplier LEDs
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LED Backlight is a consumer of one or multiple LED class devices, but devlink is currently unable to create correct supplier-producer links when the supplier is a class device. It creates instead a link where the supplier is the parent of the expected device. One consequence is that removal order is not correctly enforced. Issues happen for example with the following sections in a device tree overlay: // An LED driver chip pca9632@62 { compatible = "nxp,pca9632"; reg = <0x62>; // ... addon_led_pwm: led-pwm@3 { reg = <3>; label = "addon:led:pwm"; }; }; backlight-addon { compatible = "led-backlight"; leds = <&addon_led_pwm>; brightness-levels = <255>; default-brightness-level = <255>; }; In this example, the devlink should be created between the backlight-addon (consumer) and the pca9632@62 (supplier). Instead it is created between the backlight-addon (consumer) and the parent of the pca9632@62, which is typically the I2C bus adapter. On removal of the above overlay, the LED driver can be removed before the backlight device, resulting in: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 ... Call trace: led_put+0xe0/0x140 devm_led_release+0x6c/0x98 Another way to reproduce the bug without any device tree overlays is unbinding the LED class device (pca9632@62) before unbinding the consumer (backlight-addon): echo 11-0062 >/sys/bus/i2c/drivers/leds-pca963x/unbind echo ...backlight-dock >/sys/bus/platform/drivers/led-backlight/unbind Fix by adding a devlink between the consuming led-backlight device and the supplying LED device, as other drivers and subsystems do as well.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于led-bl背光驱动中devlink未正确链接到供应商LED,可能导致移除顺序错误。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux ae232e45acf9621f2c96b41ca3af006ac7552c33 ~ 64739adf3eef063b8e2c72b7e919eac8c6480bf0 -
LinuxLinux 5.6 -

二、漏洞 CVE-2025-68758 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-68758 的情报信息

登录查看更多情报信息。

CVE-2025-68758 其他参考 (4)

同批安全公告 · Linux · 2026-01-05 · 共 16 条

CVE-2025-68752Linux kernel 安全漏洞
CVE-2025-68751Linux kernel 安全漏洞
CVE-2025-68753Linux kernel 安全漏洞
CVE-2025-68754Linux kernel 安全漏洞
CVE-2025-68755Linux kernel 安全漏洞
CVE-2025-68756Linux kernel 安全漏洞
CVE-2025-68757Linux kernel 安全漏洞
CVE-2025-68759Linux kernel 安全漏洞
CVE-2025-68760Linux kernel 安全漏洞
CVE-2025-68761Linux kernel 安全漏洞
CVE-2025-68762Linux kernel 安全漏洞
CVE-2025-68763Linux kernel 安全漏洞
CVE-2025-68765Linux kernel 安全漏洞
CVE-2025-68764Linux kernel 安全漏洞
CVE-2025-68766Linux kernel 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-68758

暂无评论


发表评论