CVE-2025-68309: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Fix NULL pointer access by aer_info The kzalloc(GFP_KERNEL) may return NULL, so all accesses to aer_info->xxx will result in kernel panic. Fix it.
Affected products
- Linux Linux: from 6.16, before 6.17.8 (fixed in 6.17.8)
Published 2025-12-16. Last modified 2026-06-17.