CVE-2025-68236
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68236 is a vulnerability in the Linux kernel's UFS (Universal Flash Storage) subsystem, specifically in the scsi: ufs: ufs-qcom driver, related to an overcurrent protection (OCP) fault triggered during UFS power-down (PC=3). The issue arises when asserting hardware reset (HWRST) after an SSU command causes the UFS device firmware to draw a large inrush current (ICCQ), which can conflict with the regulator's low-power mode (LPM) transition and trigger an OCP fault. It was published on December 16, 2025, and affects the Linux kernel. The estimated CVSS severity is Medium, with an EPSS score of 0.000180 (Feedly, CVE.org).

Technical details

The root cause is a race condition / timing issue in the UFS power-down sequence within the ufs-qcom driver (CWE-362 or hardware timing defect). After the SSU command completes with Power_Condition=3, asserting HWRST causes the UFS device firmware to execute its reset routine, which draws a large ICCQ current for several milliseconds. Because the UFS driver immediately requests the regulator to disable (since UFS is the sole client), the regulator framework simultaneously activates LPM in hardware; if the rail is still settling while ICCQ exceeds LPM current thresholds, an OCP fault is triggered. The fix introduces a 10ms delay after asserting HWRST to allow the reset routine to complete while power rails remain active, preventing the OCP condition (Feedly, Linux Kernel Git).

Impact

Exploitation of this vulnerability can cause an overcurrent protection fault in the power regulator supplying the UFS storage device during system shutdown or power-down sequences on affected Qualcomm-based platforms. This can result in storage subsystem instability, potential data corruption if the UFS device is not cleanly powered down, and hardware-level faults that may affect system reliability and availability. The impact is limited to local hardware availability and does not directly expose confidential data or enable remote code execution (Feedly).

Mitigation and workarounds

The fix has been merged into the Linux kernel stable tree, introducing a 10ms delay after asserting HWRST during UFS power-down to allow the reset routine to complete before the regulator enters LPM. Ubuntu has released security notices addressing this vulnerability: USN-8094-1, USN-8094-2, USN-8094-3, USN-8094-4, USN-8094-5, and USN-8152-1. Users should update to the patched kernel versions provided by their Linux distribution (Ubuntu USN-8094-1, Ubuntu USN-8152-1, Linux Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management