PT-2026-1241 · Linux+5 · Linux Kernel+5

Published

2026-01-05

·

Updated

2026-05-11

·

CVE-2025-68753

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A flaw exists in the handling of DSP events within the ALSA firewire-motu module. A missing bounds check in a put user() loop could allow overwriting beyond the user buffer boundary when the buffer size is not aligned to 4 bytes. The issue resides in the DSP event handling code where data is copied using the put user() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-00896
CVE-2025-68753
ECHO-C2A4-4617-A97B
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Alsa
Debian
Linux Kernel
Linuxmint
Ubuntu
Firewire-Motu