CVE-2025-68220 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: netcp: Standardize knav_dma_open_channel to return NULL on error Make knav_dma_open_channel consistently return NULL on error instead of ERR_PTR. Currently the header include/linux/soc/ti/knav_dma.h returns NULL when the driver is disabled, but the driver implementation does not even return NULL or ERR_PTR on failure, causing inconsistency in the users. This results in a crash in netcp_free_navigator_resources as followed (trimmed): Unhandled fault: alignment exception (0x221) at 0xfffffff2 [fffffff2] *pgd=80000800207003, *pmd=82ffda003, *pte=00000000 Internal error: : 221 [#1] SMP ARM Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.17.0-rc7 #1 NONE Hardware name: Keystone PC is at knav_dma_close_channel+0x30/0x19c LR is at netcp_free_navigator_resources+0x2c/0x28c [... TRIM...] Call trace: knav_dma_close_channel from netcp_free_navigator_resources+0x2c/0x28c netcp_free_navigator_resources from netcp_ndo_open+0x430/0x46c netcp_ndo_open from __dev_open+0x114/0x29c __dev_open from __dev_change_flags+0x190/0x208 __dev_change_flags from netif_change_flags+0x1c/0x58 netif_change_flags from dev_change_flags+0x38/0xa0 dev_change_flags from ip_auto_config+0x2c4/0x11f0 ip_auto_config from do_one_initcall+0x58/0x200 do_one_initcall from kernel_init_freeable+0x1cc/0x238 kernel_init_freeable from kernel_init+0x1c/0x12c kernel_init from ret_from_fork+0x14/0x38 [... TRIM...] Standardize the error handling by making the function return NULL on all error conditions. The API is used in just the netcp_core.c so the impact is limited. Note, this change, in effect reverts commit 5b6cb43b4d62 ("net: ethernet: ti: netcp_core: return error while dma channel open issue"), but provides a less error prone implementation.
A vulnerability in the Linux kernel's handling of DMA channel errors can lead to a denial-of-service condition. The issue arises in the TI Ethernet NetCP driver, where the function knav_dma_open_channel fails to return an appropriate error indication when a channel cannot be opened. Instead of returning NULL or an error pointer, the function's inconsistent error handling can cause a crash in netcp_free_navigator_resources. This function call stack includes several network and device management operations, ultimately leading to a kernel panic due to an unhandled alignment exception. The vulnerability affects Linux kernel versions through 6.17.0-rc7.
The vulnerability has been addressed in the Linux kernel by standardizing the error handling in the knav_dma_open_channel function to consistently return NULL on all error conditions. Users should upgrade to a version of the Linux kernel that includes this fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2572c358ee434ce4b994472cceeb4043cbff5bc5 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/3afeb909c3e2e0eb19b1e20506196e5f2d9c2259 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/8427218ecbd7f8559c37972e66cb0fa06e82353b | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/90a88306eb874fe4bbdd860e6c9787f5bbc588b5 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/952637c5b9be64539cd0e13ef88db71a1df46373 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/af6b10a13fc0aee37df4a8292414cc055c263fa3 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/f9608637ecc165d7d6341df105aee44691461fb9 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/fbb53727ca789a8d27052aab4b77ca9e2a0fae2b | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | >= 6.17.0-rc7, < 6.17.0-rc8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 16, 2025 | New CVE Received | kernel.org |
Volerion