CVE-2025-68331 — Expired Pointer Dereference in Linux
Severity
7.8HIGHOSV
OSV7.2OSV3.2
No vectorEPSS
0.0%
top 86.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 22
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
When a UAS device is unplugged during data transfer, there is
a probability of a system panic occurring. The root cause is
an access to an invalid memory address during URB callback handling.
Specifically, this happens when the dma_direct_unmap_sg() function
is called within the usb_hcd_unmap_urb_for_dma() interface, but the
sg->dma_ad…
Affected Packages7 packages
▶CVEListV5linux/linuxeb2a86ae8c544be0ab04aa8169390c0669bc7148 — 6289fc489e94c9beb6be2b502ccc263663733d72+7