CVE-2025-68781 — Race Condition in Linux
10 documents7 sources
Severity
6.4MEDIUM
No vectorEPSS
0.1%
top 83.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateApr 17
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal
The delayed work item otg_event is initialized in fsl_otg_conf() and
scheduled under two conditions:
1. When a host controller binds to the OTG controller.
2. When the USB ID pin state changes (cable insertion/removal).
A race condition occurs when the device is removed via fsl_otg_remove():
the fsl_otg instance may be freed while the delayed work is …
Affected Packages8 packages
▶CVEListV5linux/linux0807c500a1a6d7fa20cbd7bbe7fea14a66112463 — 4476c73bbbb09b13a962176fca934b32d3954a2e+5
🔴Vulnerability Details
3GHSA▶
GHSA-6gqm-wpjm-6gh5: In the Linux kernel, the following vulnerability has been resolved:
usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal
The↗2026-01-13
OSV▶
CVE-2025-68781: In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal The de↗2026-01-13
📋Vendor Advisories
5Red Hat
▶
Debian▶
CVE-2025-68781: linux - In the Linux kernel, the following vulnerability has been resolved: usb: phy: f...↗2025