cbcvebase.
CVE-2025-68324
published 2025-12-18

CVE-2025-68324: In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item…

PriorityP424high7.2
EPSS
0.16%
5.9th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI host adapter is detached through imm_detach(), the imm_struct device instance is deallocated. However, the delayed work might still be pending or executing when imm_detach() is called, leading to use-after-free bugs when the work function imm_interrupt() accesses the already freed imm_struct memory. The race condition can occur as follows: CPU 0(detach thread) | CPU 1 | imm_queuecommand() | imm_queuecommand_lck() imm_detach() | schedule_delayed_work() kfree(dev) //FREE | imm_interrupt() | dev = container_of(...) //USE dev-> //USE Add disable_delayed_work_sync() in imm_detach() to guarantee proper cancellation of the delayed work item before imm_struct is deallocated.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 31ab2aad7a7b7501e904a09bf361e44671f6609231ab2aad7a7b7501e904a09bf361e44671f66092
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 48dd41fa2d6c6a0c50e714deeba06ffe7f91961b48dd41fa2d6c6a0c50e714deeba06ffe7f91961b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9e434426cc23ad5e2aad649327b59aea00294b139e434426cc23ad5e2aad649327b59aea00294b13
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ab58153ec64fa3fc9aea09ca09dc9322e0b54a7cab58153ec64fa3fc9aea09ca09dc9322e0b54a7c
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 2.6.12 < 6.12.636.12.63
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_redhat7.1MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.