CVE-2025-68176
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68176 is a NULL pointer dereference vulnerability in the Linux kernel's PCI Cadence subsystem (drivers/pci/controller/cadence). The flaw arises because cdns_pcie::ops may not be populated by all Cadence glue drivers — notably the upcoming Sophgo platform — and the code failed to check for its existence before dereferencing it. The vulnerability was published on December 16, 2025, and affects the Linux kernel across multiple stable branches. No CVSS score has been formally assigned; the EPSS score is approximately 0.024% (Feedly, EUVD).

Technical details

The root cause is a missing NULL pointer check (CWE-476: NULL Pointer Dereference) in the Cadence PCIe controller driver within the Linux kernel. When a Cadence glue driver does not populate the cdns_pcie::ops function pointer structure, any subsequent code path that dereferences ops without first verifying its existence will trigger a kernel NULL pointer dereference. This is a local, kernel-space issue — exploitation would require the ability to load or interact with the affected PCI driver on a system using a Cadence PCIe controller without ops set. The fix adds an existence check before any use of cdns_pcie::ops, as reflected in patches across multiple stable kernel trees (Feedly, Linux Kernel Git).

Impact

Successful triggering of this vulnerability causes a kernel NULL pointer dereference, which typically results in a kernel panic (system crash), leading to a denial of service on the affected host. Because the flaw is in a kernel driver, it affects the availability of the entire system rather than a single process. There is no evidence of confidentiality or integrity impact beyond the crash itself, and lateral movement or data exfiltration are not expected consequences of this specific bug (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have released patches across all affected stable branches. Fixed versions include: 5.10.247, 5.15.197, 6.1.159, 6.6.117, 6.12.58, 6.17.8, and 6.18. Debian LTS users should apply the update referenced in DLA-4436-1, and Ubuntu users should apply USN-8096-1, USN-8096-2, USN-8096-3, and USN-8116-1 as applicable. The recommended remediation is to update to a patched kernel version for your distribution (Debian LTS, Ubuntu USN-8096-1, Ubuntu USN-8116-1).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management