In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check NULL before accessing [WHAT] IGT kms_cursor_legacy's… (CVE-2025-68286)
A NULL pointer dereference vulnerability was identified and resolved in the Linux kernel's AMD GPU display driver. The issue occurs in the drm/amd/display component, specifically triggered by the IGT kms_cursor_legacy test with certain display configurations (eDP panel and DP monitors). This results in a kernel crash (NULL pointer dereference) during scanout position retrieval. The vulnerability has been fixed by adding a NULL check before accessing the pointer.
AI Analysis
Technical Summary
The Linux kernel AMD GPU display driver (drm/amd/display) contained a vulnerability where the kms_cursor_legacy test could cause a NULL pointer dereference, leading to a kernel oops and crash. This was reproducible with both eDP and DP monitors connected. The root cause was the lack of a NULL pointer check in the function dc_stream_get_scanoutpos, which was addressed by a patch that added the necessary validation to prevent dereferencing a NULL pointer. This vulnerability is tracked as CVE-2025-68286.
Potential Impact
Successful exploitation of this vulnerability results in a kernel NULL pointer dereference, causing a denial of service via a kernel crash. The CVSS vector indicates high impact on confidentiality, integrity, and availability, but no known exploits in the wild have been reported. The vulnerability requires local privileges with low complexity and no user interaction.
Mitigation Recommendations
A fix has been implemented in the Linux kernel source code, as indicated by the cherry-picked commit 621e55f1919640acab25383362b96e65f2baea3c. Users and administrators should update their Linux kernel to a version that includes this patch. Since no vendor advisory or patch links are provided, check the official Linux kernel repositories or distribution updates for the fixed version. Patch status is not yet confirmed from vendor advisories; verify current remediation guidance from official Linux kernel sources.
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check NULL before accessing [WHAT] IGT kms_cursor_legacy's… (CVE-2025-68286)
Description
A NULL pointer dereference vulnerability was identified and resolved in the Linux kernel's AMD GPU display driver. The issue occurs in the drm/amd/display component, specifically triggered by the IGT kms_cursor_legacy test with certain display configurations (eDP panel and DP monitors). This results in a kernel crash (NULL pointer dereference) during scanout position retrieval. The vulnerability has been fixed by adding a NULL check before accessing the pointer.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel AMD GPU display driver (drm/amd/display) contained a vulnerability where the kms_cursor_legacy test could cause a NULL pointer dereference, leading to a kernel oops and crash. This was reproducible with both eDP and DP monitors connected. The root cause was the lack of a NULL pointer check in the function dc_stream_get_scanoutpos, which was addressed by a patch that added the necessary validation to prevent dereferencing a NULL pointer. This vulnerability is tracked as CVE-2025-68286.
Potential Impact
Successful exploitation of this vulnerability results in a kernel NULL pointer dereference, causing a denial of service via a kernel crash. The CVSS vector indicates high impact on confidentiality, integrity, and availability, but no known exploits in the wild have been reported. The vulnerability requires local privileges with low complexity and no user interaction.
Mitigation Recommendations
A fix has been implemented in the Linux kernel source code, as indicated by the cherry-picked commit 621e55f1919640acab25383362b96e65f2baea3c. Users and administrators should update their Linux kernel to a version that includes this patch. Since no vendor advisory or patch links are provided, check the official Linux kernel repositories or distribution updates for the fixed version. Patch status is not yet confirmed from vendor advisories; verify current remediation guidance from official Linux kernel sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w4gg-v9h7-g2vh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-68286"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d39c2644c7f8477ff5
Added to database: 07/30/2026, 15:50:43 UTC
Last enriched: 07/30/2026, 18:40:45 UTC
Last updated: 09/10/2026, 19:26:53 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.