
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68334 is a denial-of-service vulnerability in the Linux kernel's platform/x86/amd/pmc module caused by a missing S0ix suspend handler for the AMD Van Gogh SoC (as used in the ASUS ROG Ally, non-X variant). When a suspend operation is attempted, the device fails to suspend correctly, and the AMD GPU driver subsequently crashes during resume due to a power hang. The vulnerability was published on December 22, 2025, and affects Linux kernel versions from the initial commit up to (but not including) the patched commits in kernel 6.17.12 and 6.18. It carries a CVSS v3.1 base score of 5.5 (Medium), with a local attack vector and high availability impact (Red Hat CVE, Red Hat Bugzilla).
The root cause is a missing power management suspend handler in the AMD PMC (Power Management Controller) kernel module for the Van Gogh SoC architecture used in the ROG Ally. Unlike the Steam Deck (which uses S3 suspend), the ROG Ally exclusively supports S0ix (modern standby) suspend; without the corresponding handler registered in the kernel, the PMC module cannot properly manage the suspend/resume lifecycle for this hardware. This results in the device failing to enter the suspended state and the AMD GPU driver encountering a power hang on resume, leading to a kernel crash (CWE classification not formally assigned). Exploitation requires local access to an affected device running a vulnerable kernel version (Red Hat Bugzilla, Red Hat CVE).
Successful triggering of this vulnerability results in a denial of service: the affected device fails to suspend, and the AMD GPU driver crashes on resume, causing system instability or an unresponsive state requiring a hard reboot. There is no confidentiality or integrity impact — the vulnerability is limited to availability (high), affecting only the local device. Lateral movement and data exfiltration are not applicable to this vulnerability (Red Hat CVE, Red Hat Bugzilla).
The fix has been incorporated into Linux kernel stable releases, with patches available for kernel versions 6.17.12 and 6.18 (commits 9654c56b111c and db4a3f0fbedb; additional backport commits 8af210df4f71 and 996092ba6df6 were added in March 2026). Ubuntu has issued security notices USN-8094-1 through USN-8094-5 addressing this vulnerability, and Debian has released a fix in linux 6.12.85+1. Users should update to a patched kernel version provided by their Linux distribution. No configuration-based workaround is documented; the recommended action is to apply the vendor-supplied kernel update (Ubuntu USN-8094-1, Red Hat Bugzilla).
The vulnerability received routine coverage from Linux security tracking sites and distribution security teams, including Ubuntu (multiple USN advisories), Debian, and Red Hat. No notable researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and distribution patch announcements.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."