
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68236 is a vulnerability in the Linux kernel's UFS (Universal Flash Storage) subsystem, specifically in the scsi: ufs: ufs-qcom driver, related to an overcurrent protection (OCP) fault triggered during UFS power-down (PC=3). The issue arises when asserting hardware reset (HWRST) after an SSU command causes the UFS device firmware to draw a large inrush current (ICCQ), which can conflict with the regulator's low-power mode (LPM) transition and trigger an OCP fault. It was published on December 16, 2025, and affects the Linux kernel. The estimated CVSS severity is Medium, with an EPSS score of 0.000180 (Feedly, CVE.org).
The root cause is a race condition / timing issue in the UFS power-down sequence within the ufs-qcom driver (CWE-362 or hardware timing defect). After the SSU command completes with Power_Condition=3, asserting HWRST causes the UFS device firmware to execute its reset routine, which draws a large ICCQ current for several milliseconds. Because the UFS driver immediately requests the regulator to disable (since UFS is the sole client), the regulator framework simultaneously activates LPM in hardware; if the rail is still settling while ICCQ exceeds LPM current thresholds, an OCP fault is triggered. The fix introduces a 10ms delay after asserting HWRST to allow the reset routine to complete while power rails remain active, preventing the OCP condition (Feedly, Linux Kernel Git).
Exploitation of this vulnerability can cause an overcurrent protection fault in the power regulator supplying the UFS storage device during system shutdown or power-down sequences on affected Qualcomm-based platforms. This can result in storage subsystem instability, potential data corruption if the UFS device is not cleanly powered down, and hardware-level faults that may affect system reliability and availability. The impact is limited to local hardware availability and does not directly expose confidential data or enable remote code execution (Feedly).
The fix has been merged into the Linux kernel stable tree, introducing a 10ms delay after asserting HWRST during UFS power-down to allow the reset routine to complete before the regulator enters LPM. Ubuntu has released security notices addressing this vulnerability: USN-8094-1, USN-8094-2, USN-8094-3, USN-8094-4, USN-8094-5, and USN-8152-1. Users should update to the patched kernel versions provided by their Linux distribution (Ubuntu USN-8094-1, Ubuntu USN-8152-1, Linux Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."