CVE-2025-68797 Details
Description
In the Linux kernel, the following vulnerability has been resolved: char: applicom: fix NULL pointer dereference in ac_ioctl Discovered by Atuin - Automated Vulnerability Discovery Engine. In ac_ioctl, the validation of IndexCard and the check for a valid RamIO pointer are skipped when cmd is 6. However, the function unconditionally executes readb(apbs[IndexCard].RamIO + VERS) at the end. If cmd is 6, IndexCard may reference a board that does not exist (where RamIO is NULL), leading to a NULL pointer dereference. Fix this by skipping the readb access when cmd is 6, as this command is a global information query and does not target a specific board context.
A NULL pointer dereference vulnerability has been identified in the Linux kernel's Applicom character driver. This issue arises in the 'ac_ioctl' function, where the validation of the 'IndexCard' and the check for a valid 'RamIO' pointer are omitted when the command ('cmd') is 6. Consequently, the function unconditionally reads from a memory location pointed to by 'RamIO', which can be NULL if 'IndexCard' references a non-existent board. This oversight leads to a NULL pointer dereference. The vulnerability affects the Linux kernel stable tree.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0b8b353e09888bccee405e0dd6feafb60360f478 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/5a6240804fb7bbd4f5f6e706955248a6f4c1abbc | kernel.org | |
| https://git.kernel.org/stable/c/74883565c621eec6cd2e35fe6d27454cf2810c23 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/82d12088c297fa1cef670e1718b3d24f414c23f7 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/d1b0452280029d05a98c75631131ee61c0b0d084 | kernel.org | |
| https://git.kernel.org/stable/c/d285517429a75423789e6408653e57b6fdfc8e54 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/f83e3e9f89181b42f6076a115d767a7552c4a39e | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jan 19, 2026 | CVE Modified | kernel.org |
| Jan 13, 2026 | New CVE Received | kernel.org |
Volerion