PT-2026-1242 · Unknown+3 · Amlogic-A4+3

CVE-2025-68754

·

Published

2025-10-21

·

Updated

2026-04-06

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the amlogic-a4 Real Time Clock (RTC) driver. A double free issue occurs because the clock obtained via devm clk get enabled() is automatically managed by the devres framework and freed on driver detachment. Redundant calls to clk disable unprepare() in the error path and remove function trigger this double free. Removing these redundant calls allows the devres framework to manage the clock lifecycle automatically.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10613
CVE-2025-68754
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Amlogic-A4