CVE-2025-68781Race Condition in Linux

10 documents7 sources
Severity
6.4MEDIUM
No vector
EPSS
0.1%
top 83.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal The delayed work item otg_event is initialized in fsl_otg_conf() and scheduled under two conditions: 1. When a host controller binds to the OTG controller. 2. When the USB ID pin state changes (cable insertion/removal). A race condition occurs when the device is removed via fsl_otg_remove(): the fsl_otg instance may be freed while the delayed work is

Affected Packages8 packages

Linuxlinux/linux_kernel3.0.06.1.160+3
Debianlinux/linux_kernel< 6.1.162-1+2
CVEListV5linux/linux0807c500a1a6d7fa20cbd7bbe7fea14a661124634476c73bbbb09b13a962176fca934b32d3954a2e+5
debiandebian/linux< linux 6.1.162-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.162-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-6gqm-wpjm-6gh5: In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal The2026-01-13
OSV
CVE-2025-68781: In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal The de2026-01-13
OSV
usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal2026-01-13

📋Vendor Advisories

5
Ubuntu
Linux kernel (GCP) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16
Red Hat
kernel: usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal2026-01-13
Debian
CVE-2025-68781: linux - In the Linux kernel, the following vulnerability has been resolved: usb: phy: f...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-68781 Impact, Exploitability, and Mitigation Steps | Wiz