PT-2025-52663 · Linux+4 · Linux Kernel+4
Syzbot
·
Published
2025-01-01
·
Updated
2026-06-16
·
CVE-2025-68335
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:H/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw in the
pcl818 ai cancel() function within the pcl818 driver. A null pointer dereference can occur if a device is detached early via pcl818 detach(), potentially leading to a general protection fault and kernel crash. This issue arises because the dev->read subdev pointer may not be initialized to point to a struct comedi async as intended. The issue was identified by Syzbot. The function pcl818 ai cancel() is involved in the vulnerability.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu
Pcl818