CVE-2025-68312 — Release of Invalid Pointer or Reference in Linux
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 85.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
usbnet: Prevents free active kevent
The root cause of this issue are:
1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0);
put the kevent work in global workqueue. However, the kevent has not yet
been scheduled when the usbnet device is unregistered. Therefore, executing
free_netdev() results in the "free active object (kevent)" error reported
here.
2. Another factor is that when calling usbnet_disconne…
Affected Packages6 packages
▶CVEListV5linux/linux8b4588b8b00b299be16a35be67b331d8fdba03f3 — 285d4b953f2ca03c358f986718dd89ee9bde632e+13