Vulnerability Bulletins

CVE-2025-68303

   
Affected software INTEL
 
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: intel: punit_ipc: fix memory corruption

This passes the address of the pointer "&punit_ipcdev" when the intent
was to pass the pointer itself "punit_ipcdev" (without the ampersand).
This means that the:

complete(&ipcdev->cmd_complete);

in intel_punit_ioc() will write to a wrong memory address corrupting it.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2025-68303