CVE-2025-68238: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: cadence: fix DMA device NULL pointer dereference The DMA device pointer `dma_dev` was being dereferenced before ensuring that `cdns_ctrl->dmac` is properly initialized. Move the assignment of `dma_dev` after successfully acquiring the DMA channel to ensure the pointer is valid before use.
Affected products
- Linux Linux: from 5.10.235, before 5.10.247 (fixed in 5.10.247); from 5.15.179, before 5.15.197 (fixed in 5.15.197); from 6.1.130, before 6.1.159 (fixed in 6.1.159); from 6.6.80, before 6.6.118 (fixed in 6.6.118); from 6.12.17, before 6.12.60 (fixed in 6.12.60); from 6.13.5, before 6.14 (fixed in 6.14); …
Published 2025-12-16. Last modified 2026-06-17.