Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-68176— PCI: cadence: Check for the existence of cdns_pcie::ops before using it

AI Predicted 5.5 Difficulty: Hard EPSS 0.20% · P10

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux40d957e6f9eb3a8a585007b8b730340c829afbdb< d5dbe92ac8a4ca6226093241f95f9cb1b0d2e0e1affected
40d957e6f9eb3a8a585007b8b730340c829afbdb< eb3d29ca0820fa3d7cccad47d2da56c9ab5469edaffected
40d957e6f9eb3a8a585007b8b730340c829afbdb< 0d0bb756f002810d249caee51f3f1c309f3cdab5affected
40d957e6f9eb3a8a585007b8b730340c829afbdb< 1810b2fd7375de88a74976dcd402b29088e479edaffected
40d957e6f9eb3a8a585007b8b730340c829afbdb< 953eb3796ef06b8ea3bf6bdde14156255bc75866affected
40d957e6f9eb3a8a585007b8b730340c829afbdb< 363448d069e29685ca37a118065121e486387af3affected
40d957e6f9eb3a8a585007b8b730340c829afbdb< 49a6c160ad4812476f8ae1a8f4ed6d15adfa6c09affected
5.9affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-68176

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PCI: cadence: Check for the existence of cdns_pcie::ops before using it
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: PCI: cadence: Check for the existence of cdns_pcie::ops before using it cdns_pcie::ops might not be populated by all the Cadence glue drivers. This is going to be true for the upcoming Sophgo platform which doesn't set the ops. Hence, add a check to prevent NULL pointer dereference. [mani: reworded subject and description]
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查cdns_pcie::ops是否存在,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 40d957e6f9eb3a8a585007b8b730340c829afbdb ~ d5dbe92ac8a4ca6226093241f95f9cb1b0d2e0e1 -
LinuxLinux 5.9 -

II. Public POCs for CVE-2025-68176

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-68176

登录查看更多情报信息。

Other References for CVE-2025-68176 (7)

Same Patch Batch · Linux · 2025-12-16 · 157 CVEs total

CVE-2025-682639.8 CRITICALksmbd: ipc: fix use-after-free in ipc_msg_send_request
CVE-2025-682849.8 CRITICALlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()
CVE-2025-683159.8 CRITICALf2fs: fix to detect potential corrupted nid in free_nid_list
CVE-2025-681929.8 CRITICALnet: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
CVE-2025-683019.8 CRITICALnet: atlantic: fix fragment overflow handling in RX path
CVE-2025-682859.8 CRITICALlibceph: fix potential use-after-free in have_mon_and_osd_map()
CVE-2025-403509.8 CRITICALnet/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ
CVE-2025-682568.8 HIGHstaging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
CVE-2025-683048.8 HIGHBluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-682558.8 HIGHstaging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
CVE-2025-683148.8 HIGHdrm/msm: make sure last_fence is always updated
CVE-2025-682268.8 HIGHsmb: client: fix incomplete backport in cfids_invalidation_worker()
CVE-2025-403628.8 HIGHceph: fix multifs mds auth caps issue
CVE-2025-682508.2 HIGHhung_task: fix warnings caused by unaligned lock pointers
CVE-2025-682077.8 HIGHdrm/xe/guc: Synchronize Dead CT worker with unbind
CVE-2025-682087.8 HIGHbpf: account for current allocated stack depth in widen_imprecise_scalars()
CVE-2025-681797.8 HIGHs390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP
CVE-2025-681837.8 HIGHima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr
CVE-2025-681817.8 HIGHdrm/radeon: Remove calls to drm_put_dev()
CVE-2025-682657.8 HIGHnvme: fix admin request_queue lifetime

Showing top 20 of 157 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-68176

No comments yet


Leave a comment