
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68230 is a vulnerability in the Linux kernel's drm/amdgpu driver that causes a GPU page fault after hibernation in PF (Physical Function) passthrough environments. The issue was published on December 16, 2025, and affects Linux kernel versions prior to the patched releases 6.12.60, 6.17.10, and 6.18. The root cause is that Mode1 reset during hibernation does not restore the compute partition mode on resume, leading to incorrect register states and out-of-bounds memory access. Feedly estimates the severity as Medium, and the EPSS score is approximately 0.017% (Feedly, EUVD).
The vulnerability is classified under out-of-bounds access (CWE-125/CWE-787) triggered by improper state restoration in the drm/amdgpu kernel driver. During hibernation, a Mode1 GPU reset occurs, but the compute partition mode is not restored on resume — specifically, registers mmCP_HYP_XCP_CTL and mmCP_PSP_XCP_CTL are left in an incorrect state. When the Command Processor (CP) subsequently accesses the MQD (Memory Queue Descriptor) Buffer Object, it uses a wrong stride size, causing an out-of-bounds access on the MQD BO and triggering a GPU page fault. The fix ensures gfx_v9_4_3_switch_compute_partition() is called during resume from hibernation; KFD resume is handled separately and does not need to be part of the partition switch (Feedly).
Exploitation of this vulnerability results in a GPU page fault that can crash or destabilize the system in PF passthrough environments (e.g., virtualized workloads using AMD GPU passthrough). The primary impact is on availability — systems running workloads such as coralgemm after a hibernate/resume cycle may experience kernel panics or GPU subsystem failures. There is no known confidentiality or integrity impact, and the vulnerability is not remotely exploitable; it requires local access and a specific hardware/software configuration (Feedly, EUVD).
The Linux kernel maintainers have released patches addressing this vulnerability in stable branches. Fixed versions include Linux 6.12.60, 6.17.10, and 6.18. Administrators should update their kernel packages to these versions or later. Ubuntu has issued security notices USN-8094-1 through USN-8094-5 and USN-8152-1 addressing this and related kernel vulnerabilities. Oracle Linux has also issued a corresponding advisory. No configuration-based workaround is documented; upgrading the kernel is the recommended remediation (Ubuntu USN-8094-1, Ubuntu USN-8152-1, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."