CVE-2025-68754: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm The clock obtained via devm_clk_get_enabled() is automatically managed by devres and will be disabled and freed on driver detach. Manually calling clk_disable_unprepare() in error path and remove function causes double free. Remove the redundant clk_disable_unprepare() calls from the probe error path and aml_rtc_remove(), allowing the devm framework to automatically manage the clock lifecycle.

Affected products

  • Linux Linux: from 6.13, before 6.17.13 (fixed in 6.17.13); from 6.18, before 6.18.2 (fixed in 6.18.2)

Published 2026-01-05. Last modified 2026-06-17.