
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68332 is a vulnerability in the Linux kernel's comedi subsystem, specifically in the c6xdigio driver, related to invalid PnP (Plug and Play) driver unregistration. It was published on December 22, 2025, and affects multiple Linux kernel versions across various distributions including Red Hat, Debian, and Ubuntu. The Feedly threat intelligence data estimates a MEDIUM severity for this CVE, with an EPSS score of approximately 0.032% (Red Hat CVE, Red Hat Bugzilla).
The vulnerability resides in the Linux kernel's comedi subsystem within the c6xdigio driver, where improper PnP driver unregistration logic can lead to undefined behavior — likely a use-after-free or improper resource cleanup condition (CWE classification not formally published, but consistent with improper resource management, CWE-404 or CWE-416). The flaw is triggered during driver unload or device removal when the PnP driver is unregistered incorrectly. Patches have been committed to the stable kernel tree across multiple branches (kernel.org patch 1, kernel.org patch 2).
Successful exploitation of this vulnerability could allow a local attacker or unprivileged user with access to the affected system to trigger kernel instability, potentially leading to a denial of service (system crash) or, in more severe scenarios, privilege escalation depending on the exact memory corruption primitive exposed. The impact is primarily on availability and integrity of the affected Linux system. Systems running affected kernel versions with the comedi c6xdigio driver loaded are at risk (Red Hat CVE).
The primary remediation is to apply the patched Linux kernel versions provided by upstream and downstream distributors. Red Hat, Debian, and Ubuntu have all issued updates addressing this vulnerability. Specifically:
As a workaround where patching is not immediately possible, unloading or blacklisting the c6xdigio kernel module (modprobe -r c6xdigio or adding it to /etc/modprobe.d/blacklist.conf) can reduce exposure if the hardware is not in use.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."