CVE-2026-68325
Last modified
CVE-2026-68325 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET parsers, it does not reject a fifth entry before incrementing the map size. Check the capacity at the common found label before parsing the HID and UID or writing the entry.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET parsers, it does not reject a fifth entry before incrementing the map size. Check the capacity at the common found label before parsing the HID and UID or writing the entry.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < 9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < e5e0098f8cd82f8b3c8687a8f686309565d51745; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < afe7ea0520c49586703f210865ace2d70b017e48; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < 1e31d2394e0db69541b1591d46c5ad6431c81db3; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < abe5d7962f09adada9c4fb25b816dddd3f97c55d; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < e5ebe8544df1a1c3611739a8622156094fe470df; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < 030a8e84f8f1b6e96f469c84a13a225c3699910b; >= ca3bf5d47cec8b7614bcb2e9132c40081d6d81db, < fb80117fddb5b477218dc99bb53911b72c3847f8 |
| Linux | Linux | 4.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68325?
How severe is CVE-2026-68325?
How do I fix CVE-2026-68325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6832Hermes WebUI contains an arbitrary file deletion vulnerabili…8.1
- CVE-2026-68320In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-68321In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68322In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68323In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68324In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68326In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-68327In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68328In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68329In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-6833The a+HRD developed by aEnrich has a SQL Injection vulnerabi…7.1
- CVE-2026-68330In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-68325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
