CVE-2025-68314
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-68314 is a use-after-free vulnerability in the Linux kernel's DRM/MSM (Direct Rendering Manager for Qualcomm Adreno GPUs) subsystem, caused by last_fence not being consistently updated in vm-bind contexts. The bug allows resources to be freed while still in use when a context is closed, leading to kernel faults. It was published on December 16, 2025, and affects Linux kernel versions from commit 92395af63a99 up to (but not including) the fix commits. The CVSS base score is not yet formally assigned, with Feedly estimating severity as Medium and an EPSS score of 0.000180 (Feedly, ENISA EUVD).

Technical details

The root cause is a race condition / improper resource lifecycle management (CWE-416: Use After Free) in the drm/msm driver. The last_fence variable is used to synchronize GPU work completion in vm-bind contexts, but was previously only updated in the kernel-managed path rather than the vm-bind path. When a context is closed before the fence is waited upon, GPU resources (such as GPU virtual memory mappings) can be freed while the GPU is still actively using them, triggering page faults. The fix moves last_fence updates to the vm-bind path to ensure proper synchronization before resource teardown (ENISA EUVD, Patchwork).

Impact

Successful triggering of this vulnerability results in kernel faults (crashes) due to GPU resources being accessed after they have been freed, impacting system availability. On systems using Qualcomm Adreno GPUs (common in ARM-based devices and some embedded/mobile Linux platforms), this could cause denial of service through kernel panics or GPU hangs. There is no evidence of confidentiality or integrity impact beyond the stability of the affected system (Feedly, ENISA EUVD).

Exploitability

There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution for CVE-2025-68314. The EPSS score is very low at 0.000180, indicating a minimal probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures have been added by Nessus (plugin 279002) and Qualys (IDs 6031981, 6032019) (Feedly, Tenable).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this vulnerability in two stable branches: commit 8ee817ceafba266d9c6f3a09babd2ac7441d9a2b (targeting Linux 6.17.8) and commit 86404a9e3013d814a772ac407573be5d3cd4ee0d (targeting Linux 6.18). Users running affected kernel versions on systems with Qualcomm Adreno GPUs should update to Linux 6.17.8 or 6.18 (or later). No configuration-based workaround is available; patching is the only remediation (ENISA EUVD, Kernel Stable).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48120HIGH8.6
  • Linux Debian logoLinux Debian
  • kakoune
NoNoAug 07, 2026
CVE-2026-42170HIGH7.8
  • Linux Debian logoLinux Debian
  • gimp-help-browser
NoYesAug 08, 2026
CVE-2026-71870MEDIUM4.8
  • Python logoPython
  • pypdf2
NoYesAug 07, 2026
CVE-2026-68082NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 08, 2026
CVE-2026-68081NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management