Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-68334
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68334 is a denial-of-service vulnerability in the Linux kernel's platform/x86/amd/pmc module caused by a missing S0ix suspend handler for the AMD Van Gogh SoC (as used in the ASUS ROG Ally, non-X variant). When a suspend operation is attempted, the device fails to suspend correctly, and the AMD GPU driver subsequently crashes during resume due to a power hang. The vulnerability was published on December 22, 2025, and affects Linux kernel versions from the initial commit up to (but not including) the patched commits in kernel 6.17.12 and 6.18. It carries a CVSS v3.1 base score of 5.5 (Medium), with a local attack vector and high availability impact (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is a missing power management suspend handler in the AMD PMC (Power Management Controller) kernel module for the Van Gogh SoC architecture used in the ROG Ally. Unlike the Steam Deck (which uses S3 suspend), the ROG Ally exclusively supports S0ix (modern standby) suspend; without the corresponding handler registered in the kernel, the PMC module cannot properly manage the suspend/resume lifecycle for this hardware. This results in the device failing to enter the suspended state and the AMD GPU driver encountering a power hang on resume, leading to a kernel crash (CWE classification not formally assigned). Exploitation requires local access to an affected device running a vulnerable kernel version (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful triggering of this vulnerability results in a denial of service: the affected device fails to suspend, and the AMD GPU driver crashes on resume, causing system instability or an unresponsive state requiring a hard reboot. There is no confidentiality or integrity impact — the vulnerability is limited to availability (high), affecting only the local device. Lateral movement and data exfiltration are not applicable to this vulnerability (Red Hat CVE, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2025-68334. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is limited to users with local access to affected AMD Van Gogh SoC devices (e.g., ROG Ally non-X) running unpatched Linux kernels (Red Hat CVE, Feedly).

Mitigation and workarounds

The fix has been incorporated into Linux kernel stable releases, with patches available for kernel versions 6.17.12 and 6.18 (commits 9654c56b111c and db4a3f0fbedb; additional backport commits 8af210df4f71 and 996092ba6df6 were added in March 2026). Ubuntu has issued security notices USN-8094-1 through USN-8094-5 addressing this vulnerability, and Debian has released a fix in linux 6.12.85+1. Users should update to a patched kernel version provided by their Linux distribution. No configuration-based workaround is documented; the recommended action is to apply the vendor-supplied kernel update (Ubuntu USN-8094-1, Red Hat Bugzilla).

Community reactions

The vulnerability received routine coverage from Linux security tracking sites and distribution security teams, including Ubuntu (multiple USN advisories), Debian, and Red Hat. No notable researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and distribution patch announcements.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Affected

sid

linux: 6.17.12-1

Fixed

trixie

linux: 6.12.85-1

Fixed

Ubuntu

Fixed

bionic (esm-infra)

linux

Affected

bionic (fips-updates)

linux-fips

Affected

bionic (fips)

linux-fips

Affected

devel

linux

Not Affected

focal (esm-infra)

linux

Affected

focal (fips-updates)

linux-fips

Affected

focal (fips)

linux-fips

Affected

jammy

linux

Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

kernel-rt.src

Affected

RHEL 10

kernel.src

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.17
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management