CVE-2025-68342 — Out-of-bounds Read in Linux
Severity
7.2HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data
The URB received in gs_usb_receive_bulk_callback() contains a struct
gs_host_frame. The length of the data after the header depends on the
gs_host_frame hf::flags and the active device features (e.g. time
stamping).
Introduce a new function gs_usb_get_minimum_length() and check that we have
at least received the required amount of data befo…
Affected Packages6 packages
▶CVEListV5linux/linuxd08e973a77d128b25e01a08c34d89593fdf222da — 4ffac725154cf6a253f5e6aa0c8946232b6a0af5+4