CVE-2025-68176

Linux kernel - Null Pointer Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: PCI: cadence: Check for the existence of cdns_pcie::ops before using it cdns_pcie::ops might not be populated by all the Cadence glue drivers. This is going to be true for the upcoming Sophgo platform which doesn't set the ops. Hence, add a check to prevent NULL pointer dereference. [mani: reworded subject and description]

Scores

EPSS 0.0006
EPSS Percentile 18.3%

Details

Status published
Products (22)
linux/Kernel 5.11.0 - 5.15.197linux
linux/Kernel 5.16.0 - 6.1.159linux
linux/Kernel 5.9.0 - 5.10.247linux
linux/Kernel 6.13.0 - 6.17.8linux
linux/Kernel 6.2.0 - 6.6.117linux
linux/Kernel 6.7.0 - 6.12.58linux
Linux/Linux < 5.9
Linux/Linux 40d957e6f9eb3a8a585007b8b730340c829afbdb - 0d0bb756f002810d249caee51f3f1c309f3cdab5
Linux/Linux 40d957e6f9eb3a8a585007b8b730340c829afbdb - 1810b2fd7375de88a74976dcd402b29088e479ed
Linux/Linux 40d957e6f9eb3a8a585007b8b730340c829afbdb - 363448d069e29685ca37a118065121e486387af3
... and 12 more
Published Dec 16, 2025
Tracked Since Feb 18, 2026