CVE-2025-68316

Linux Kernel 6.13-6.17.8 - Invalid Error Return Value in UFS Core Probe

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix invalid probe error return value After DME Link Startup, the error return value is set to the MIPI UniPro GenericErrorCode which can be 0 (SUCCESS) or 1 (FAILURE). Upon failure during driver probe, the error code 1 is propagated back to the driver probe function which must return a negative value to indicate an error, but 1 is not negative, so the probe is considered to be successful even though it failed. Subsequently, removing the driver results in an oops because it is not in a valid state. This happens because none of the callers of ufshcd_init() expect a non-negative error code. Fix the return value and documentation to match actual usage.

Scores

EPSS 0.0003
EPSS Percentile 7.8%

Details

Status published
Products (7)
linux/Kernel 6.13.0 - 6.17.8linux
Linux/Linux < 6.13
Linux/Linux 6.13
Linux/Linux 6.17.8 - 6.17.*
Linux/Linux 6.18
Linux/Linux 69f5eb78d4b0cc978fe83dd2bfea1b67547290bf - a2b32bc1d9e359a9f90d0de6af16699facb10935
Linux/Linux 69f5eb78d4b0cc978fe83dd2bfea1b67547290bf - df96dbe1af7f6591c09f862f1226d3619b07e1b6
Published Dec 16, 2025
Tracked Since Feb 18, 2026