CVE-2025-68290

Source
https://cve.org/CVERecord?id=CVE-2025-68290
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68290.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68290
Downstream
Related
Published
2025-12-16T15:06:11.202Z
Modified
2026-03-20T12:46:20.862538Z
Summary
most: usb: fix double free on late probe failure
Details

In the Linux kernel, the following vulnerability has been resolved:

most: usb: fix double free on late probe failure

The MOST subsystem has a non-standard registration function which frees the interface on registration failures and on deregistration.

This unsurprisingly leads to bugs in the MOST drivers, and a couple of recent changes turned a reference underflow and use-after-free in the USB driver into several double free and a use-after-free on late probe failures.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68290.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
723de0f9171eeb49a3ae98cae82ebbbb992b3a7c
Fixed
90e6ce2b1b19fb8b9d4afee69f40e4c6a4791154
Fixed
a4c4118c2af284835b16431bbfe77e0130c06fef
Fixed
0dece48660be16918ecf2dbdc7193e8be03e1693
Fixed
993bfdc3842893c394de13c8200c338ebb979589
Fixed
2274767dc02b756b25e3db1e31c0ed47c2a78442
Fixed
8d8ffefe3d5d8b7b73efb866db61130107299c5c
Fixed
baadf2a5c26e802a46573eaad331b427b49aaa36

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68290.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.10.247
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.197
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.159
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.119
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.61
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68290.json"