cbcvebase.
CVE-2025-68290
published 2025-12-16

CVE-2025-68290: In the Linux kernel, the following vulnerability has been resolved: most: usb: fix double free on late probe failure The MOST subsystem has a non-standard…

PriorityP423high7.8
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: most: usb: fix double free on late probe failure The MOST subsystem has a non-standard registration function which frees the interface on registration failures and on deregistration. This unsurprisingly leads to bugs in the MOST drivers, and a couple of recent changes turned a reference underflow and use-after-free in the USB driver into several double free and a use-after-free on late probe failures.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 90e6ce2b1b19fb8b9d4afee69f40e4c6a479115490e6ce2b1b19fb8b9d4afee69f40e4c6a4791154
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < a4c4118c2af284835b16431bbfe77e0130c06fefa4c4118c2af284835b16431bbfe77e0130c06fef
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 0dece48660be16918ecf2dbdc7193e8be03e16930dece48660be16918ecf2dbdc7193e8be03e1693
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 993bfdc3842893c394de13c8200c338ebb979589993bfdc3842893c394de13c8200c338ebb979589
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 2274767dc02b756b25e3db1e31c0ed47c2a784422274767dc02b756b25e3db1e31c0ed47c2a78442
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < 8d8ffefe3d5d8b7b73efb866db61130107299c5c8d8ffefe3d5d8b7b73efb866db61130107299c5c
linuxlinux>= 723de0f9171eeb49a3ae98cae82ebbbb992b3a7c < baadf2a5c26e802a46573eaad331b427b49aaa36baadf2a5c26e802a46573eaad331b427b49aaa36
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.6.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.2.0 < 6.6.1196.6.119
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-azure-5.15

CVSS provenance

osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.