Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-68808— media: vidtv: initialize local pointers upon transfer of memory ownership

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于转移内存所有权后未将本地指针初始化为NULL,可能导致释放后重用和双重释放。

CVSS 7.8 · High EPSS 0.13% · P3

Possible ATT&CK Techniques 1 AI

T1135 · Network Share Discovery

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 3be8037960bccd13052cfdeba8805ad785041d70< c342e294dac4988c8ada759b2f057246e48c5108 affected
3be8037960bccd13052cfdeba8805ad785041d70< 12ab6ebb37789b84073e83e4d9b14a5e0d133323 affected
3be8037960bccd13052cfdeba8805ad785041d70< 3caa18d35f1dabe85a3dd31bc387f391ac9f9b4e affected
3be8037960bccd13052cfdeba8805ad785041d70< fb9bd6d8d314b748e946ed6555eb4a956ee8c4d8 affected
3be8037960bccd13052cfdeba8805ad785041d70< a69c7fd603bf5ad93177394fbd9711922ee81032 affected
3be8037960bccd13052cfdeba8805ad785041d70< 30f4d4e5224a9e44e9ceb3956489462319d804ce affected
3be8037960bccd13052cfdeba8805ad785041d70< 98aabfe2d79f74613abc2b0b1cef08f97eaf5322 affected
5.10 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-68808

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: vidtv: initialize local pointers upon transfer of memory ownership
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: vidtv: initialize local pointers upon transfer of memory ownership vidtv_channel_si_init() creates a temporary list (program, service, event) and ownership of the memory itself is transferred to the PAT/SDT/EIT tables through vidtv_psi_pat_program_assign(), vidtv_psi_sdt_service_assign(), vidtv_psi_eit_event_assign(). The problem here is that the local pointer where the memory ownership transfer was completed is not initialized to NULL. This causes the vidtv_psi_pmt_create_sec_for_each_pat_entry() function to fail, and in the flow that jumps to free_eit, the memory that was freed by vidtv_psi_*_table_destroy() can be accessed again by vidtv_psi_*_event_destroy() due to the uninitialized local pointer, so it is freed once again. Therefore, to prevent use-after-free and double-free vulnerability, local pointers must be initialized to NULL when transferring memory ownership.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于转移内存所有权后未将本地指针初始化为NULL,可能导致释放后重用和双重释放。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 3be8037960bccd13052cfdeba8805ad785041d70 ~ c342e294dac4988c8ada759b2f057246e48c5108 -
Linux Linux 5.10 -

II. Public POCs for CVE-2025-68808

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-68808

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-01-13 · 93 CVEs total

CVE-2025-71068 9.8 CRITICAL svcrdma: bound check rq_pages index in inline path
CVE-2025-68794 9.8 CRITICAL iomap: adjust read range correctly for non-block-aligned positions
CVE-2025-68811 9.8 CRITICAL svcrdma: use rc_pageoff for memcpy byte offset
CVE-2025-68817 9.8 CRITICAL ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
CVE-2025-68775 9.8 CRITICAL net/handshake: duplicate handshake cancellations leak socket
CVE-2025-68809 9.1 CRITICAL ksmbd: vfs: fix race on m_flags in vfs_cache
CVE-2025-71093 9.1 CRITICAL e1000: fix OOB in e1000_tbi_should_accept()
CVE-2025-71095 9.1 CRITICAL net: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-68818 8.8 HIGH scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"
CVE-2025-71072 8.2 HIGH shmem: fix recovery on rename failures
CVE-2025-68799 8.1 HIGH caif: fix integer underflow in cffrml_receive()
CVE-2025-68803 8.0 HIGH NFSD: NFSv4 file creation neglects setting ACL
CVE-2025-71078 7.8 HIGH powerpc/64s/slb: Fix SLB multihit issue during SLB preload
CVE-2025-68801 7.8 HIGH mlxsw: spectrum_router: Fix neighbour use-after-free
CVE-2025-71082 7.8 HIGH Bluetooth: btusb: revert use of devm_kzalloc in btusb
CVE-2025-68795 7.8 HIGH ethtool: Avoid overflowing userspace buffer on stats query
CVE-2025-68793 7.8 HIGH drm/amdgpu: fix a job->pasid access race in gpu recovery
CVE-2025-68822 7.8 HIGH Input: alps - fix use-after-free bugs caused by dev3_register_work
CVE-2025-68792 7.8 HIGH tpm2-sessions: Fix out of range indexing in name_size
CVE-2025-71066 7.8 HIGH net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change

Showing top 20 of 93 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-68808

No comments yet


Leave a comment