CVE-2025-68167

Linux Kernel - Use-After-Free in gpiolib DebugFS

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix invalid pointer access in debugfs If the memory allocation in gpiolib_seq_start() fails, the s->private field remains uninitialized and is later dereferenced without checking in gpiolib_seq_stop(). Initialize s->private to NULL before calling kzalloc() and check it before dereferencing it.

Scores

EPSS 0.0002
EPSS Percentile 7.1%

Details

Status published
Products (10)
linux/Kernel 6.13.0 - 6.17.8linux
linux/Kernel 6.9.0 - 6.12.58linux
Linux/Linux < 6.9
Linux/Linux 6.12.58 - 6.12.*
Linux/Linux 6.17.8 - 6.17.*
Linux/Linux 6.18
Linux/Linux 6.9
Linux/Linux e348544f7994d252427ed3ae637c7081cbb90f66 - 2f6115ad8864cf3f48598f26c74c7c8e5c391919
Linux/Linux e348544f7994d252427ed3ae637c7081cbb90f66 - 3c91c8f424d3e44c8645ab765a38773e58afb07d
Linux/Linux e348544f7994d252427ed3ae637c7081cbb90f66 - 70180a6031056096c93ed2f47c41803268bdd91c
Published Dec 16, 2025
Tracked Since Feb 18, 2026