CVE-2025-68312: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. However, the kevent has not yet been scheduled when the usbnet device is unregistered. Therefore, executing free_netdev() results in the "free active object (kevent)" error reported here. 2. Another factor is that when calling usbnet_disconnect()->unregister_netdev(), if the usbnet device is up, ndo_stop() is executed to cancel the kevent. However, because the device is not up, ndo_stop() is not executed. The solution to this problem is to cancel the kevent before executing free_netdev().

Affected products

  • Linux Linux: from 5.4.211, before 5.4.302 (fixed in 5.4.302); from 5.10.137, before 5.10.247 (fixed in 5.10.247); from 5.15.61, before 5.15.197 (fixed in 5.15.197); from 4.9.326, before 4.10 (fixed in 4.10); from 4.14.291, before 4.15 (fixed in 4.15); from 4.19.256, before 4.20 (fixed in 4.20); …

Published 2025-12-16. Last modified 2026-06-17.