CVE-2025-68332
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68332 is a vulnerability in the Linux kernel's comedi subsystem, specifically in the c6xdigio driver, related to invalid PnP (Plug and Play) driver unregistration. It was published on December 22, 2025, and affects multiple Linux kernel versions across various distributions including Red Hat, Debian, and Ubuntu. The Feedly threat intelligence data estimates a MEDIUM severity for this CVE, with an EPSS score of approximately 0.032% (Red Hat CVE, Red Hat Bugzilla).

Technical details

The vulnerability resides in the Linux kernel's comedi subsystem within the c6xdigio driver, where improper PnP driver unregistration logic can lead to undefined behavior — likely a use-after-free or improper resource cleanup condition (CWE classification not formally published, but consistent with improper resource management, CWE-404 or CWE-416). The flaw is triggered during driver unload or device removal when the PnP driver is unregistered incorrectly. Patches have been committed to the stable kernel tree across multiple branches (kernel.org patch 1, kernel.org patch 2).

Impact

Successful exploitation of this vulnerability could allow a local attacker or unprivileged user with access to the affected system to trigger kernel instability, potentially leading to a denial of service (system crash) or, in more severe scenarios, privilege escalation depending on the exact memory corruption primitive exposed. The impact is primarily on availability and integrity of the affected Linux system. Systems running affected kernel versions with the comedi c6xdigio driver loaded are at risk (Red Hat CVE).

Mitigation and workarounds

The primary remediation is to apply the patched Linux kernel versions provided by upstream and downstream distributors. Red Hat, Debian, and Ubuntu have all issued updates addressing this vulnerability. Specifically:

  • Debian: Fixed in linux 6.1.162-1 (oldstable/Bullseye) and linux 5.10.249-1 (oldoldstable/Buster via LTS) (Debian Tracker)
  • Ubuntu: Fixed in USN-8094-1 through USN-8094-5, USN-8179-1 through USN-8179-4, USN-8184-1, USN-8185-1, USN-8185-2, USN-8203-1, USN-8258-1, USN-8260-1, USN-8265-1 (Ubuntu USN-8094-1)
  • Upstream kernel: Patches committed to stable branches at kernel.org

As a workaround where patching is not immediately possible, unloading or blacklisting the c6xdigio kernel module (modprobe -r c6xdigio or adding it to /etc/modprobe.d/blacklist.conf) can reduce exposure if the hardware is not in use.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management