cbcvebase.
CVE-2025-68312
published 2025-12-16

CVE-2025-68312: In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the…

PriorityP421high7.8
EPSS
0.18%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. However, the kevent has not yet been scheduled when the usbnet device is unregistered. Therefore, executing free_netdev() results in the "free active object (kevent)" error reported here. 2. Another factor is that when calling usbnet_disconnect()->unregister_netdev(), if the usbnet device is up, ndo_stop() is executed to cancel the kevent. However, because the device is not up, ndo_stop() is not executed. The solution to this problem is to cancel the kevent before executing free_netdev().

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 135199a2edd459d2b123144efcd7f9bcd95128e4 < 88a38b135d69f5db9024ff6527232f1b51be891588a38b135d69f5db9024ff6527232f1b51be8915
linuxlinux>= 4.14.291 < 4.154.15
linuxlinux>= 4.19.256 < 4.204.20
linuxlinux>= 4.9.326 < 4.104.10
linuxlinux>= 5.10.137 < 5.10.2475.10.247
linuxlinux>= 5.15.61 < 5.15.1975.15.197
linuxlinux>= 5.18.18 < 5.195.19
linuxlinux>= 5.19.2 < 5.205.20
linuxlinux>= 5.4.211 < 5.4.3025.4.302
linuxlinux>= 635fd8953e4309b54ca6a81bed1d4a87668694f4 < 43005002b60ef3424719ecda16d124714b45da3b43005002b60ef3424719ecda16d124714b45da3b
linuxlinux>= 8b4588b8b00b299be16a35be67b331d8fdba03f3 < 285d4b953f2ca03c358f986718dd89ee9bde632e285d4b953f2ca03c358f986718dd89ee9bde632e
linuxlinux>= a69e617e533edddf3fa3123149900f36e0a6dc74 < 3a10619fdefd3051aeb14860e4d4335529b4e94d3a10619fdefd3051aeb14860e4d4335529b4e94d
linuxlinux>= a69e617e533edddf3fa3123149900f36e0a6dc74 < 9a579d6a39513069d298eee70770bbac8a1485659a579d6a39513069d298eee70770bbac8a148565
linuxlinux>= a69e617e533edddf3fa3123149900f36e0a6dc74 < 2ce1de32e05445d77fc056f6ff8339cfb78a5f842ce1de32e05445d77fc056f6ff8339cfb78a5f84
linuxlinux>= a69e617e533edddf3fa3123149900f36e0a6dc74 < 5158fb8da162e3982940f30cd01ed77bdf42c6fc5158fb8da162e3982940f30cd01ed77bdf42c6fc
linuxlinux>= a69e617e533edddf3fa3123149900f36e0a6dc74 < 420c84c330d1688b8c764479e5738bbdbf0a33de420c84c330d1688b8c764479e5738bbdbf0a33de
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.