CVE-2025-68808

NONE EPSS 6.9%
Published Jan 13, 20265mo ago · Modified Jun 17, 20261w ago
Find Similar
Published Jan 13, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: initialize local pointers upon transfer of memory ownership vidtv_channel_si_init() creates a temporary list (program, service, event) and ownership of the memory itself is transferred to the PAT/SDT/EIT tables through vidtv_psi_pat_program_assign(), vidtv_psi_sdt_service_assign(), vidtv_psi_eit_event_assign(). The problem here is that the local pointer where the memory ownership transfer was completed is not initialized to NULL. This causes the vidtv_psi_pmt_create_sec_for_each_pat_entry() function to fail, and in the flow that jumps to free_eit, the memory that was freed by vidtv_psi_*_table_destroy() can be accessed again by vidtv_psi_*_event_destroy() due to the uninitialized local pointer, so it is freed once again. Therefore, to prevent use-after-free and double-free vulnerability, local pointers must be initialized to NULL when transferring memory ownership.

Threat Intelligence

EPSS Exploit Probability
6.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

References 7

  • git.kernel.org https://git.kernel.org/stable/c/12ab6ebb37789b84073e83e4d9b14a5e0d133323
  • git.kernel.org https://git.kernel.org/stable/c/30f4d4e5224a9e44e9ceb3956489462319d804ce
  • git.kernel.org https://git.kernel.org/stable/c/3caa18d35f1dabe85a3dd31bc387f391ac9f9b4e
  • git.kernel.org https://git.kernel.org/stable/c/98aabfe2d79f74613abc2b0b1cef08f97eaf5322
  • git.kernel.org https://git.kernel.org/stable/c/a69c7fd603bf5ad93177394fbd9711922ee81032
  • git.kernel.org https://git.kernel.org/stable/c/c342e294dac4988c8ada759b2f057246e48c5108
  • git.kernel.org https://git.kernel.org/stable/c/fb9bd6d8d314b748e946ed6555eb4a956ee8c4d8

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.