PT-2025-52906 · Linux+2 · Linux Kernel+2

CVE-2025-68370

·

Published

2025-11-10

·

Updated

2026-04-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s coresight component, specifically within the tmc subsystem. The issue stems from a missing handle for events, which is crucial for retrieving auxiliary event data for each CPU in perf mode. The absence of this handle in the coresight path prevents dependent devices from accessing necessary information. This can lead to a kernel oops when attempting to record performance data using the perf command, for example, with the command perf record -e cs etm//k -C 0-9 dd if=/dev/zero of=/dev/null. The error manifests as an inability to handle a kernel paging request at a specific virtual address.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12427
CVE-2025-68370
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu