CVE-2025-68228

Source
https://cve.org/CVERecord?id=CVE-2025-68228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68228
Downstream
Published
2025-12-16T13:57:21.011Z
Modified
2025-12-16T20:35:36.052541Z
Summary
drm/plane: Fix create_in_format_blob() return value
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/plane: Fix createinformat_blob() return value

createinformat_blob() is either supposed to return a valid pointer or an error, but never NULL. The caller will dereference the blob when it is not an error, and thus will oops if NULL returned. Return proper error values in the failure cases.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68228.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0d6dcd741c266389bbf0a8758f537b3a171ac32a
Fixed
860f93f4fce1e733b8a2474f6bfa153243d775f3
Fixed
cead55e24cf9e092890cf51c0548eccd7569defa

Affected versions

v6.*
v6.15
v6.15-rc6
v6.15-rc7
v6.16
v6.16-rc1
v6.16-rc2
v6.16-rc3
v6.16-rc4
v6.16-rc5
v6.16-rc6
v6.16-rc7
v6.17
v6.17-rc1
v6.17-rc2
v6.17-rc3
v6.17-rc4
v6.17-rc5
v6.17-rc6
v6.17-rc7
v6.17.1
v6.17.2
v6.17.3
v6.17.4
v6.17.5
v6.17.6
v6.17.7
v6.17.8
v6.17.9
v6.18-rc1
v6.18-rc2
v6.18-rc3
v6.18-rc4
v6.18-rc5
v6.18-rc6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68228.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.17.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68228.json"