CVE-2025-68281: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list "struct sdca_control" declares "values" field as integer array. But the memory allocated to it is of char array. This causes crash for sdca_parse_function API. This patch addresses the issue by allocating correct data size.

Affected products

  • Linux Linux: from 6.17, before 6.17.12 (fixed in 6.17.12)

Published 2025-12-16. Last modified 2026-06-17.