Junglewise Threat Intelligence

CVE-2025-68170: Linux Kernel Radeon DRM double-free in radeon_kms.c

CVE-2025-68170 · Severity: high · CVSS 7.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Radeon graphics driver, which manages how the operating system communicates with AMD/Radeon video cards. A technical error in how the system handles memory during hardware setup could cause the system to crash or 'explode' if the driver fails to load correctly. This could lead to a loss of system availability or potentially allow an attacker to gain unauthorized control over the system.

Technical details

A double-free vulnerability exists in the Linux kernel's Radeon DRM driver (drivers/gpu/drm/radeon/radeon_kms.c). The issue stems from the driver manually calling kfree() on the 'rdev' structure, which is already managed by the devres (device resource management) framework via devm_drm_dev_alloc(). If a driver probe fails, both the manual kfree() and the automatic devres cleanup attempt to release the same memory, leading to a kernel crash or potential memory corruption. This is a local vulnerability requiring low privileges. Patches have been released in various stable kernel branches including 6.12.58 and 6.17.8.

Affected products

  • Linux Linux Kernel 6.12, 6.17, 6.18

Timeline

  • 2025-12-16: advisory: CVE published by kernel.org
  • 2025-10-28: patched: Initial fix committed to the Linux kernel tree

References

Related threats