CVE-2025-68235

Source
https://cve.org/CVERecord?id=CVE-2025-68235
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68235.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68235
Downstream
Related
Published
2025-12-16T14:08:29.396Z
Modified
2026-03-12T02:18:07.097422Z
Summary
nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
Details

In the Linux kernel, the following vulnerability has been resolved:

nouveau/firmware: Add missing kfree() of nvkmfalconfw::boot

nvkmfalconfw::boot is allocated, but no one frees it. This causes a kmemleak warning.

Make sure this data is deallocated.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68235.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2541626cfb794e57ba0575a6920826f591f7ced0
Fixed
7d1977b4ae5c50e1aafc5c51500fc08bd7afd6a0
Fixed
6492add9a3a163d5e0390428d2636adc3e61b883
Fixed
2bba02a39bfb383bd1a95868d532c0917e38f9e7
Fixed
949f1fd2225baefbea2995afa807dba5cbdb6bd3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68235.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.118
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.60
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68235.json"