CVE-2025-68303
Last modified
CVE-2025-68303 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corruption This passes the address of the pointer "&punit_ipcdev" when the intent was to pass the pointer itself "punit_ipcdev" (without the ampersand). This means that the: complete(&ipcdev->cmd_complete); in intel_punit_ioc() will write to a wrong memory address corrupting it.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corruption This passes the address of the pointer "&punit_ipcdev" when the intent was to pass the pointer itself "punit_ipcdev" (without the ampersand). This means that the: complete(&ipcdev->cmd_complete); in intel_punit_ioc() will write to a wrong memory address corrupting it.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= fdca4f16f57da76a8e68047923588a87d1c01f0a, < 15d560cdf5b36c51fffec07ac2a983ab3bff4cb2; >= fdca4f16f57da76a8e68047923588a87d1c01f0a, < 46e9d6f54184573dae1dcbcf6685a572ba6f4480; >= fdca4f16f57da76a8e68047923588a87d1c01f0a, < 3e7442c5802146fd418ba3f68dcb9ca92b5cec83; >= fdca4f16f57da76a8e68047923588a87d1c01f0a, < a21615a4ac6fecbb586d59fe2206b63501021789; >= fdca4f16f57da76a8e68047923588a87d1c01f0a, < c2ee6d38996775a19bfdf20cb01a9b8698cb0baa; >= fdca4f16f57da76a8e68047923588a87d1c01f0a, < 9b9c0adbc3f8a524d291baccc9d0c04097fb4869 |
| Linux | Linux | 4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68303?
How severe is CVE-2025-68303?
How do I fix CVE-2025-68303?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68298In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68299In the Linux kernel, the following vulnerability has been re…
- CVE-2025-6830Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2025-68300In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68301In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-68302In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-68304In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-68305In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68306In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68307In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68308In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68309In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-68303?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
