PT-2025-53014 · Linux+3 · Linux Kernel+3

Published

2025-11-03

·

Updated

2026-04-06

·

CVE-2025-68748

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The Linux kernel’s Panthor DRM driver contains a use-after-free issue. The panthor fw unplug() function frees firmware memory sections, but pending firmware events may still be processing at that time. The process fw events work() function could then attempt to access this freed memory. The issue is addressed by calling disable work sync() to drain and prevent future invocation of process fw events work().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-04169
CVE-2025-68748
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Debian
Linux Kernel
Linuxmint
Ubuntu