PT-2025-52883 · Linux+3 · Linux Kernel+3

Published

2025-12-05

·

Updated

2026-05-28

·

CVE-2025-68347

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) Windows (affected versions not specified)
Description A flaw exists in the Linux kernel related to ALSA and firewire-motu, specifically a buffer overflow in the hwdep read() function when handling DSP events. The issue occurs when a user provides a buffer smaller than the event header size (8 bytes), potentially allowing more bytes to be written to the user buffer than requested. The problem is addressed by clamping the copy size using min t(). A separate issue enables unauthenticated SYSTEM-level Remote Code Execution (RCE) in Windows.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2026:21706
ALSA-2026:21745
AZL-73096
BDU:2026-01161
CVE-2025-68347
ECHO-DA22-2BDE-8B83
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu