CVE-2025-68343 — Out-of-bounds Read in Linux
Severity
7.2HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 92.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header
The driver expects to receive a struct gs_host_frame in
gs_usb_receive_bulk_callback().
Use struct_group to describe the header of the struct gs_host_frame and
check that we have at least received the header before accessing any
members of it.
To resubmit the URB, do not dereference the pointer chain
"dev->parent->hf_size_rx" but use "pa…
Affected Packages7 packages
▶CVEListV5linux/linuxd08e973a77d128b25e01a08c34d89593fdf222da — 18cbce43363c9f84b90a92d57df341155eee0697+5