CVE-2025-68773
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68773 is a buffer overrun vulnerability in the Linux kernel's SPI FSL-CPM (Freescale CPM) driver. The driver failed to verify that transfer sizes are even before switching to 16-bit mode, causing out-of-bounds writes when odd-sized transfers occur. It affects Linux kernel versions from the introduction of commit fc96ec826bce through multiple stable branches, with fixes available in versions 6.1.160, 6.6.120, 6.12.64, 6.18.3, and 6.19-rc2. The vulnerability was published on January 13, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).

Technical details

The root cause is a missing input validation check (CWE class: improper input validation / out-of-bounds write) in the fsl-cpm SPI driver. Commit fc96ec826bce introduced 16-bit transfer mode for large even-sized transfers but omitted the parity check. The vulnerability was latent until commit 8ad6249c51d0 ("eeprom: at25: convert to spi-mem API") changed the at25 EEPROM driver to use dynamically allocated bounce buffers sized exactly to the transfer length rather than a fixed PAGE_SIZE buffer — when an odd-sized transfer is issued, the 16-bit mode operation writes one byte beyond the allocated buffer boundary. Exploitation requires local access with low privileges and the presence of the fsl-cpm SPI driver with an attached at25 EEPROM device (Red Hat CVE, Feedly).

Impact

Successful exploitation causes a kernel buffer overrun that can crash the system, resulting in a denial of service. The vulnerability has no confidentiality or integrity impact — only availability is affected, as the overrun can destabilize or panic the kernel. The scope is limited to the local system running the affected fsl-cpm SPI driver, with no known path to lateral movement or data exfiltration (Feedly, Red Hat CVE).

Mitigation and workarounds

Apply the patched kernel versions for your maintained branch: Linux 6.1.160, 6.6.120, 6.12.64, 6.18.3, or 6.19-rc2 and later. Microsoft has released a patch for the Azure Linux 3 kernel (azl3_kernel_6.6.119.3-3). Debian, Ubuntu (USN-8177-1, USN-8179-1, USN-8183-1, USN-8184-1, USN-8185-1, USN-8203-1, USN-8245-1, USN-8257-1, USN-8258-1, USN-8260-1, USN-8265-1), and SUSE have also issued advisories with updated packages. If immediate patching is not possible, restrict access to SPI device interfaces and monitor for unexpected kernel crashes related to SPI or EEPROM operations (Red Hat CVE, Feedly, Ubuntu USN-8177-1).

Community reactions

Red Hat has published a CVE record and is tracking the vulnerability. Debian issued security advisories (DSA-6126-1 and DLA-4475-1) covering this CVE in updated kernel packages. Ubuntu issued multiple security notices (USN-8177-1 through USN-8265-1 series) addressing this and related kernel vulnerabilities. No notable independent researcher commentary or significant social media discussion has been identified for this vulnerability (Red Hat CVE, Ubuntu USN-8177-1, Debian LTS).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management