CVE-2025-68338

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2025
Last modified:
23/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: dsa: microchip: Don&amp;#39;t free uninitialized ksz_irq<br /> <br /> If something goes wrong at setup, ksz_irq_free() can be called on<br /> uninitialized ksz_irq (for example when ksz_ptp_irq_setup() fails). It<br /> leads to freeing uninitialized IRQ numbers and/or domains.<br /> <br /> Use dsa_switch_for_each_user_port_continue_reverse() in the error path<br /> to iterate only over the fully initialized ports.

Impact