cbcvebase.
CVE-2025-68343
published 2025-12-23

CVE-2025-68343: In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header…

PriorityP420high7.8
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header The driver expects to receive a struct gs_host_frame in gs_usb_receive_bulk_callback(). Use struct_group to describe the header of the struct gs_host_frame and check that we have at least received the header before accessing any members of it. To resubmit the URB, do not dereference the pointer chain "dev->parent->hf_size_rx" but use "parent->hf_size_rx" instead. Since "urb->context" contains "parent", it is always defined, while "dev" is not defined if the URB it too short.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= d08e973a77d128b25e01a08c34d89593fdf222da < 18cbce43363c9f84b90a92d57df341155eee069718cbce43363c9f84b90a92d57df341155eee0697
linuxlinux>= d08e973a77d128b25e01a08c34d89593fdf222da < 3433680b759646efcacc64fe36aa2e51ae34b8f03433680b759646efcacc64fe36aa2e51ae34b8f0
linuxlinux>= d08e973a77d128b25e01a08c34d89593fdf222da < 616eee3e895b8ca0028163fcb1dce5e3e9dea322616eee3e895b8ca0028163fcb1dce5e3e9dea322
linuxlinux>= d08e973a77d128b25e01a08c34d89593fdf222da < f31693dc3a584c0ad3937e857b59dbc1a7ed2b87f31693dc3a584c0ad3937e857b59dbc1a7ed2b87
linuxlinux>= d08e973a77d128b25e01a08c34d89593fdf222da < 6fe9f3279f7d2518439a7962c5870c6e9ecbadcf6fe9f3279f7d2518439a7962c5870c6e9ecbadcf
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 3.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.2.0 < 6.6.1196.6.119
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv7.2HIGH
vendor_redhat6.1MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.