CVE-2025-68312

UnknownEPSS 0.17%

Last modified

CVE-2025-68312 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. However, the kevent has not yet been scheduled when the usbnet device is unregistered. Therefore, executing free_netdev() results in the "free active object (kevent)" error reported here. 2. Another factor is that when calling usbnet_disconnect()->unregister_netdev(), if the usbnet device is up, ndo_stop() is executed to cancel the kevent. However, because the device is not up, ndo_stop() is not executed. The solution to this problem is to cancel the kevent before executing free_netdev().

Metrics

EPSS Probability
0.17%

6.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 8b4588b8b00b299be16a35be67b331d8fdba03f3, < 285d4b953f2ca03c358f986718dd89ee9bde632e; >= 135199a2edd459d2b123144efcd7f9bcd95128e4, < 88a38b135d69f5db9024ff6527232f1b51be8915; >= 635fd8953e4309b54ca6a81bed1d4a87668694f4, < 43005002b60ef3424719ecda16d124714b45da3b; >= a69e617e533edddf3fa3123149900f36e0a6dc74, < 3a10619fdefd3051aeb14860e4d4335529b4e94d; >= a69e617e533edddf3fa3123149900f36e0a6dc74, < 9a579d6a39513069d298eee70770bbac8a148565; >= a69e617e533edddf3fa3123149900f36e0a6dc74, < 2ce1de32e05445d77fc056f6ff8339cfb78a5f84; >= a69e617e533edddf3fa3123149900f36e0a6dc74, < 5158fb8da162e3982940f30cd01ed77bdf42c6fc; >= a69e617e533edddf3fa3123149900f36e0a6dc74, < 420c84c330d1688b8c764479e5738bbdbf0a33de; d2d6b530d89b0a912148018027386aa049f0a309; e2a521a7dcc463c5017b4426ca0804e151faeff7; 7f77dcbc030c2faa6d8e8a594985eeb34018409e; d49bb8cf9bfaa06aa527eb30f1a52a071da2e32f; db3b738ae5f726204876f4303c49cfdf4311403f; >= 5.4.211, < 5.4.302; >= 5.10.137, < 5.10.247; >= 5.15.61, < 5.15.197; >= 4.9.326, < 4.10; >= 4.14.291, < 4.15; >= 4.19.256, < 4.20; >= 5.18.18, < 5.19; >= 5.19.2, < 5.20
LinuxLinux6.0

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-68312?
In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. However, the kevent has not yet been scheduled when the usbnet device is unregistered. Therefore, executing free_netdev() results in the "free active object (kevent)" error reported here. 2. Another factor is that when calling usbnet_disconnect()->unregister_netdev(), if the usbnet device is up, ndo_stop() is executed to cancel the kevent. However, because the device is not up, ndo_stop() is not executed. The solution to this problem is to cancel the kevent before executing free_netdev().
How severe is CVE-2025-68312?
Severity scoring for CVE-2025-68312 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2025-68312?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-68312?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST