🛡️ CVE-2025-68184 — kernel

🟠 CVSS 7.1 — High ✅ No Known Exploit NVD
7.1
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

drm/mediatek: Disable AFBC support on Mediatek DRM driver

In the Linux kernel, the following vulnerability has been resolved:

drm/mediatek: Disable AFBC support on Mediatek DRM driver

Commit c410fa9b07c3 ("drm/mediatek: Add AFBC support to Mediatek DRM

driver") added AFBC support to Mediatek DRM and enabled the

32x8/split/sparse modifier.

However, this is currently broken on Mediatek MT8188 (Genio 700 EVK

platform); tested using upstream Kernel and Mesa (v25.2.1), AFBC is used by

default since Mesa v25.0.

Kernel trace reports vblank timeouts constantly, and the render is garbled:

```

[CRTC:62:crtc-0] vblank wait timed out

WARNING: CPU: 7 PID: 70 at drivers/gpu/drm/drm_atomic_helper.c:1835 drm_atomic_helper_wait_for_vblanks.part.0+0x24c/0x27c

[...]

Hardware name: MediaTek Genio-700 EVK (DT)

Workqueue: events_unbound commit_work

pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)

pc : drm_atomic_helper_wait_for_vblanks.part.0+0x24c/0x27c

lr : drm_atomic_helper_wait_for_vblanks.part.0+0x24c/0x27c

sp : ffff80008337bca0

x29: ffff80008337bcd0 x28: 0000000000000061 x27: 0000000000000000

x26: 0000000000000001 x25: 0000000000000000 x24: ffff0000c9dcc000

x23: 0000000000000001 x22: 0000000000000000 x21: ffff0000c66f2f80

x20: ffff0000c0d7d880 x19: 0000000000000000 x18: 000000000000000a

x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000000

x14: 0000000000000000 x13: 74756f2064656d69 x12: 742074696177206b

x11: 0000000000000058 x10: 0000000000000018 x9 : ffff800082396a70

x8 : 0000000000057fa8 x7 : 0000000000000cce x6 : ffff8000823eea70

x5 : ffff0001fef5f408 x4 : ffff80017ccee000 x3 : ffff0000c12cb480

x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000c12cb480

Call trace:

drm_atomic_helper_wait_for_vblanks.part.0+0x24c/0x27c (P)

drm_atomic_helper_commit_tail_rpm+0x64/0x80

commit_tail+0xa4/0x1a4

commit_work+0x14/0x20

process_one_work+0x150/0x290

worker_thread+0x2d0/0x3ec

kthread+0x12c/0x210

ret_from_fork+0x10/0x20

---[ end trace 0000000000000000 ]---

```

Until this gets fixed upstream, disable AFBC support on this platform, as

it's currently broken with upstream Mesa.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability high.

Affected software

CVE-2025-68184 is recorded against 2 packages.

  • kernel (from 6.13.0 up to 6.17.8)
  • unknown

Timeline and source

Published on 16 December 2025 and last revised on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2025-68184 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity High
CVSS Score 7.1
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-12-16
Updated 2026-08-12
Modified 2026-08-06
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.13.0 6.17.8
unknown

Similar Threats

Site Security Check

Is kernel part of your stack?

CVE-2025-68184 is rated CVSS 7.1 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.