A buffer overflow in the Linux kernel's ALSA firewire-motu component was assigned CVE-2025-68347 after maintainers found that hwdep_read() could copy more bytes to a user buffer than requested while processing DSP events. The flaw affects code introduced in kernel 5.16 and occurs when the supplied buffer is smaller than the 8-byte event header, resulting in an out-of-bounds write classified as CWE-787. Upstream kernel maintainers fixed the issue by clamping the copy length with min_t() in sound/firewire/motu/motu-hwdep.c.
The Linux kernel CVE team said the bug has been resolved in multiple branches, including 6.12.63, 6.17.13, 6.18.2, and 6.19-rc1, and advised users to update to the latest stable kernel release instead of cherry-picking patches. Red Hat rated the vulnerability Moderate with a CVSS v3 score of 7.1 and said fixes for Red Hat Enterprise Linux 8 kernel and kernel-rt packages were released, while RHEL 6, 7, 7 kernel-rt, 9, 9 kernel-rt, and 10 were listed as not affected because the vulnerable code is not present.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat states that fixes for CVE-2025-68347 were released for Red Hat Enterprise Linux 8 kernel and kernel-rt packages via advisories RHSA-2026:21706 and RHSA-2026:21745.
Red Hat's CVE entry for CVE-2025-68347 was made public, describing the Linux kernel ALSA firewire-motu out-of-bounds write and listing affected and unaffected RHEL versions.
Greg Kroah-Hartman published the Linux kernel CVE announcement for CVE-2025-68347, describing the ALSA firewire-motu hwdep_read() buffer overflow and recommending updates to the latest stable kernel releases.
The Linux kernel CVE announcement says the hwdep_read() buffer overflow was fixed using min_t() and that fixes were included in kernel versions 6.12.63, 6.17.13, 6.18.2, and 6.19-rc1.
The Linux kernel CVE announcement states that the bug behind CVE-2025-68347 was introduced in Linux kernel 5.16 in the ALSA firewire-motu subsystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.