CVE-2025-68194 — Infinite Loop in Linux
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 79.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
media: imon: make send_packet() more robust
syzbot is reporting that imon has three problems which result in
hung tasks due to forever holding device lock [1].
First problem is that when usb_rx_callback_intf0() once got -EPROTO error
after ictx->dev_present_intf0 became true, usb_rx_callback_intf0()
resubmits urb after printk(), and resubmitted urb causes
usb_rx_callback_intf0() to again get -EPROTO error. This results in
pri…
Affected Packages6 packages
▶CVEListV5linux/linux21677cfc562a27e099719d413287bc8d1d24deb7 — 519737af11c03590819a6eec2ad532cfdb87ea63+8
🔴Vulnerability Details
23📋Vendor Advisories
24🕵️Threat Intelligence
1💬Community
1Bugzilla▶
CVE-2025-68194 kernel: Linux kernel: imon media driver denial of service via USB error handling↗2025-12-16