All findings

CVE-2025-40345, CVE-2025-68352, CVE-2025-68797 high

Linux records three CVEs discovered by Atuin

Public Linux CVE and fix records explicitly name Atuin on memory-safety and crash bugs in USB storage, CH341 SPI, and the applicom driver.

Bug class
Heap corruption, out-of-bounds access, and NULL dereference
Affected codebase
Linux USB storage, CH341 SPI, and applicom drivers
Credited system
Atuin Automated Vulnerability Discovery Engine
Disclosed
January 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: The Linux CNA descriptions and accepted fix records explicitly state that Atuin discovered the flaws. CVE.org provides the public identifiers and upstream references.

Summary

The three Linux records cover a USB-storage heap-corruption path, an out-of-bounds access in the CH341 SPI driver, and a NULL dereference in the legacy applicom driver.

Attribution

The public Linux CNA descriptions explicitly use discovery language naming Atuin. That is stronger than attributing AI use from the reporter’s laboratory alone.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.