Home

Description

In the Linux kernel, the following vulnerability has been resolved: most: usb: fix double free on late probe failure The MOST subsystem has a non-standard registration function which frees the interface on registration failures and on deregistration. This unsurprisingly leads to bugs in the MOST drivers, and a couple of recent changes turned a reference underflow and use-after-free in the USB driver into several double free and a use-after-free on late probe failures.

PUBLISHED Reserved 2025-12-16 | Published 2025-12-16 | Updated 2025-12-16 | Assigner Linux

Product status

Default status
unaffected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before 90e6ce2b1b19fb8b9d4afee69f40e4c6a4791154
affected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before a4c4118c2af284835b16431bbfe77e0130c06fef
affected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before 0dece48660be16918ecf2dbdc7193e8be03e1693
affected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before 993bfdc3842893c394de13c8200c338ebb979589
affected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before 2274767dc02b756b25e3db1e31c0ed47c2a78442
affected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before 8d8ffefe3d5d8b7b73efb866db61130107299c5c
affected

723de0f9171eeb49a3ae98cae82ebbbb992b3a7c (git) before baadf2a5c26e802a46573eaad331b427b49aaa36
affected

Default status
affected

5.6
affected

Any version before 5.6
unaffected

5.10.247 (semver)
unaffected

5.15.197 (semver)
unaffected

6.1.159 (semver)
unaffected

6.6.119 (semver)
unaffected

6.12.61 (semver)
unaffected

6.17.11 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/90e6ce2b1b19fb8b9d4afee69f40e4c6a4791154

git.kernel.org/...c/a4c4118c2af284835b16431bbfe77e0130c06fef

git.kernel.org/...c/0dece48660be16918ecf2dbdc7193e8be03e1693

git.kernel.org/...c/993bfdc3842893c394de13c8200c338ebb979589

git.kernel.org/...c/2274767dc02b756b25e3db1e31c0ed47c2a78442

git.kernel.org/...c/8d8ffefe3d5d8b7b73efb866db61130107299c5c

git.kernel.org/...c/baadf2a5c26e802a46573eaad331b427b49aaa36

cve.org (CVE-2025-68290)

nvd.nist.gov (CVE-2025-68290)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.