CVE-2025-68167: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix invalid pointer access in debugfs If the memory allocation in gpiolib_seq_start() fails, the s->private field remains uninitialized and is later dereferenced without checking in gpiolib_seq_stop(). Initialize s->private to NULL before calling kzalloc() and check it before dereferencing it.

Affected products

  • Linux Linux: from 6.9, before 6.12.58 (fixed in 6.12.58); from 6.13, before 6.17.8 (fixed in 6.17.8)

Published 2025-12-16. Last modified 2026-07-30.