PT-2025-52883 · Linux+4 · Linux Kernel+4

CVE-2025-68347

·

Published

2025-12-05

·

Updated

2026-08-19

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) Windows (affected versions not specified)
Description A flaw exists in the Linux kernel related to ALSA and firewire-motu, specifically a buffer overflow in the hwdep read() function when handling DSP events. The issue occurs when a user provides a buffer smaller than the event header size (8 bytes), potentially allowing more bytes to be written to the user buffer than requested. The problem is addressed by clamping the copy size using min t(). A separate issue enables unauthenticated SYSTEM-level Remote Code Execution (RCE) in Windows.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21706
ALSA-2026:21745
AZL-73096
BDU:2026-01161
CVE-2025-68347
ECHO-DA22-2BDE-8B83
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
RHSA-2026:21706
RHSA-2026:21745
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20564-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1
USN-8440-1

Affected Products

Debian
Linuxmint
Linux Kernel
Rocky Linux
Ubuntu