CVE-2025-68281: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list "struct sdca_control" declares "values" field as integer array. But the memory allocated to it is of char array. This causes crash for sdca_parse_function API. This patch addresses the issue by allocating correct data size.
Affected products
- Linux Linux: from 6.17, before 6.17.12 (fixed in 6.17.12)
Published 2025-12-16. Last modified 2026-06-17.