CVE-2025-68777
In the Linux kernel, the following vulnerability has been resolved:
Input: ti_am335x_tsc - fix off-by-one error in wire_order validation
The current validation 'wire_order[i] > ARRAY_SIZE(config_pins)' allows wire_order[i] to equal ARRAY_SIZE(config_pins), which causes out-of-bounds access when used as index in 'config_pins[wire_order[i]]'.
Since config_pins has 4 elements (indices 0-3), the valid range for wire_order should be 0-3. Fix the off-by-one error by using >= instead of > in the validation check.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/08c0b561823a7026364efb38ed7f4a3af48ccfcd
- https://git.kernel.org/stable/c/136abe173a3cc2951d70c6e51fe7abdbadbb204b
- https://git.kernel.org/stable/c/248d3a73a0167dce15ba100477c3e778c4787178
- https://git.kernel.org/stable/c/40e3042de43ffa0017a8460ff9b4cad7b8c7cb96
- https://git.kernel.org/stable/c/84e4d3543168912549271b34261f5e0f94952d6e
- https://git.kernel.org/stable/c/a7ff2360431561b56f559d3a628d1f096048d178
- https://git.kernel.org/stable/c/bf95ec55805828c4f2b5241fb6b0c12388548570
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68777",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "a7ff2360431561b56f559d3a628d1f096048d178",
"versionType": "git"
},
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "136abe173a3cc2951d70c6e51fe7abdbadbb204b",
"versionType": "git"
},
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "08c0b561823a7026364efb38ed7f4a3af48ccfcd",
"versionType": "git"
},
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "bf95ec55805828c4f2b5241fb6b0c12388548570",
"versionType": "git"
},
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "84e4d3543168912549271b34261f5e0f94952d6e",
"versionType": "git"
},
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "40e3042de43ffa0017a8460ff9b4cad7b8c7cb96",
"versionType": "git"
},
{
"status": "affected",
"version": "bb76dc09ddfc135c6c5e8eb7d3c583bfa8bdd439",
"lessThan": "248d3a73a0167dce15ba100477c3e778c4787178",
"versionType": "git"
}
],
"programFiles": [
"drivers/input/touchscreen/ti_am335x_tsc.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.248",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.198",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.64",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.3",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/input/touchscreen/ti_am335x_tsc.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-01-13T16:15:57.310",
"references": [
{
"url": "https://git.kernel.org/stable/c/08c0b561823a7026364efb38ed7f4a3af48ccfcd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/136abe173a3cc2951d70c6e51fe7abdbadbb204b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/248d3a73a0167dce15ba100477c3e778c4787178",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/40e3042de43ffa0017a8460ff9b4cad7b8c7cb96",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/84e4d3543168912549271b34261f5e0f94952d6e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a7ff2360431561b56f559d3a628d1f096048d178",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bf95ec55805828c4f2b5241fb6b0c12388548570",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ti_am335x_tsc - fix off-by-one error in wire_order validation\n\nThe current validation 'wire_order[i] > ARRAY_SIZE(config_pins)' allows\nwire_order[i] to equal ARRAY_SIZE(config_pins), which causes out-of-bounds\naccess when used as index in 'config_pins[wire_order[i]]'.\n\nSince config_pins has 4 elements (indices 0-3), the valid range for\nwire_order should be 0-3. Fix the off-by-one error by using >= instead\nof > in the validation check."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nInput: ti_am335x_tsc - corrige error de uno en la validación de 'wire_order'\n\nLa validación actual 'wire_order[i] > ARRAY_SIZE(config_pins)' permite que wire_order[i] sea igual a ARRAY_SIZE(config_pins), lo que causa acceso fuera de límites cuando se usa como índice en 'config_pins[wire_order[i]]'.\n\nDado que config_pins tiene 4 elementos (índices 0-3), el rango válido para wire_order debería ser 0-3. Corrige el error de uno usando '>=' en lugar de '>' en la comprobación de validación."
}
],
"lastModified": "2026-06-17T09:59:34.293",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}