CVE-2025-68230
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68230 is a vulnerability in the Linux kernel's drm/amdgpu driver that causes a GPU page fault after hibernation in PF (Physical Function) passthrough environments. The issue was published on December 16, 2025, and affects Linux kernel versions prior to the patched releases 6.12.60, 6.17.10, and 6.18. The root cause is that Mode1 reset during hibernation does not restore the compute partition mode on resume, leading to incorrect register states and out-of-bounds memory access. Feedly estimates the severity as Medium, and the EPSS score is approximately 0.017% (Feedly, EUVD).

Technical details

The vulnerability is classified under out-of-bounds access (CWE-125/CWE-787) triggered by improper state restoration in the drm/amdgpu kernel driver. During hibernation, a Mode1 GPU reset occurs, but the compute partition mode is not restored on resume — specifically, registers mmCP_HYP_XCP_CTL and mmCP_PSP_XCP_CTL are left in an incorrect state. When the Command Processor (CP) subsequently accesses the MQD (Memory Queue Descriptor) Buffer Object, it uses a wrong stride size, causing an out-of-bounds access on the MQD BO and triggering a GPU page fault. The fix ensures gfx_v9_4_3_switch_compute_partition() is called during resume from hibernation; KFD resume is handled separately and does not need to be part of the partition switch (Feedly).

Impact

Exploitation of this vulnerability results in a GPU page fault that can crash or destabilize the system in PF passthrough environments (e.g., virtualized workloads using AMD GPU passthrough). The primary impact is on availability — systems running workloads such as coralgemm after a hibernate/resume cycle may experience kernel panics or GPU subsystem failures. There is no known confidentiality or integrity impact, and the vulnerability is not remotely exploitable; it requires local access and a specific hardware/software configuration (Feedly, EUVD).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this vulnerability in stable branches. Fixed versions include Linux 6.12.60, 6.17.10, and 6.18. Administrators should update their kernel packages to these versions or later. Ubuntu has issued security notices USN-8094-1 through USN-8094-5 and USN-8152-1 addressing this and related kernel vulnerabilities. Oracle Linux has also issued a corresponding advisory. No configuration-based workaround is documented; upgrading the kernel is the recommended remediation (Ubuntu USN-8094-1, Ubuntu USN-8152-1, Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management