Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68296

11
FAUCET Score

CVE-2025-68296 addresses a race condition in the Linux kernel's drm, fbcon, and vga_switcheroo components, specifically affecting the fbcon setup during VGA switching. This vulnerability could lead to out-of-bounds (OOB) access in fbcon_remap_all() due to a lack of proper console lock protection. While a CVSS score is not available, the FAUCET Risk Score of 7/100 suggests a low to moderate severity, with the potential impact being system instability or crashes. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion and media coverage, including a security update from openSUSE.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
2.6.34CNA affecteddefault affected
LinuxLinux
>= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a, >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 482330f8261b4bea8146d9bd69c1199e5dfcbb5c, >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 711ebd961190def4c69ea24b2f0be75e995af24a, >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < eb76d0f5553575599561010f24c277cc5b31d003CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

Remediation

Patch Available

Vendor Patches (23)

microsoftpatch availablevia msrc
Product: 21443-17084Fixed in: 6.6.143.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.141.1-1 on Azure Linux 3.0Fixed in: 6.6.143.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-aws (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.3
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime (questing)Fixed in: 6.17.0-1008.9
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime-6.17 (noble)Fixed in: 6.17.0-1008.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.17 (noble)Fixed in: 6.17.0-1010.10~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-raspi (questing)Fixed in: 6.17.0-1010.10
ubuntupatch availablevia ubuntu_usn
Product: linux-oem-6.17 (noble)Fixed in: 6.17.0-1017.17
ubuntupatch availablevia ubuntu_usn
Product: linux-aws-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-hwe-6.17 (noble)Fixed in: 6.17.0-19.19~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle-6.17 (noble)Fixed in: 6.17.0-1009.9~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux (questing)Fixed in: 6.17.0-19.19
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp (questing)Fixed in: 6.17.0-1009.9
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle (questing)Fixed in: 6.17.0-1009.9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel

Vendor Advisories (8)

ubuntuUSN-8152-1

Linux kernel (OEM) vulnerabilities

Apr 6, 2026
ubuntuUSN-8094-5

Linux kernel (Raspberry Pi) vulnerabilities

Apr 1, 2026
ubuntuUSN-8094-4

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8094-3

Linux kernel (Real-time) vulnerabilities

Mar 23, 2026
ubuntuUSN-8094-2

Linux kernel vulnerabilities

Mar 17, 2026
ubuntuUSN-8094-1

Linux kernel vulnerabilities

Mar 16, 2026
redhatCVE-2025-68296Moderate

kernel: Linux kernel: Denial of Service due to race condition in fbcon setup

Dec 16, 2025
microsoft2025-Dec/CVE-2025-68296Moderate

drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup

Dec 9, 2025

References

git.kernel.org / stable/c/05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a
git.kernel.org / stable/c/482330f8261b4bea8146d9bd69c1199e5dfcbb5c
git.kernel.org / stable/c/711ebd961190def4c69ea24b2f0be75e995af24a
git.kernel.org / stable/c/eb76d0f5553575599561010f24c277cc5b31d003