
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68290 is a double free and use-after-free vulnerability in the Linux kernel's MOST subsystem USB driver, triggered during late probe failures. The MOST subsystem uses a non-standard registration function that frees the interface on both registration failures and deregistration, leading to memory corruption bugs in the USB driver. It affects Linux kernel versions from 5.6 through 6.17.10, as well as Azure Linux 3 kernel version 6.6.117.1-1. The vulnerability was published on December 16, 2025, with patches released shortly after. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is improper memory management (CWE-415: Double Free / CWE-416: Use After Free) in the most_usb driver within the Linux kernel. The MOST subsystem's non-standard most_register_interface() function frees the interface object on both registration failure and deregistration paths; recent refactoring changes converted a reference underflow and use-after-free into multiple double free conditions and a use-after-free on late probe failures. Exploitation requires local access with low privileges and can be triggered by connecting a USB device that causes a probe failure in the MOST USB driver, such as during USB hotplug events or driver initialization errors (Microsoft MSRC, Feedly). Upstream kernel patches are available via the stable tree at multiple commit references (e.g., 90e6ce2b, a4c4118c, 0dece486, 993bfdc3, 2274767d).
Successful exploitation by a low-privileged local attacker can result in kernel memory corruption through double free and use-after-free conditions, potentially leading to denial of service (kernel panic/system crash), information disclosure by reading freed kernel memory, or privilege escalation to root. The vulnerability affects the kernel's core memory management integrity, and exploitation during USB device hotplug events could destabilize the entire system. Azure Linux 3 environments running kernel 6.6.117.1-1 are specifically identified as affected (Microsoft MSRC, Feedly).
dmesg, /var/log/kern.log) showing BUG: KASAN: double-free or use-after-free errors in the most_usb or most kernel module; kernel oops or panic traces referencing most_usb.ko./var/crash/) generated after USB hotplug events involving MOST-compatible devices.Patches are available in the following Linux kernel stable releases: 5.10.247, 5.15.197, 6.1.159, 6.6.119, 6.12.61, 6.17.11, and 6.18. Azure Linux 3 users running kernel 6.6.117.1-1 should upgrade to 6.6.119 or later. As a temporary workaround if patching is not immediately possible, restrict physical USB device access to reduce the attack surface and prevent untrusted USB devices from being connected to affected systems. Ubuntu security notices USN-8094-x, USN-8096-x, USN-8116-1, USN-8152-1, and Debian LTS advisory DLA-4436-1 also address this vulnerability for their respective distributions (Microsoft MSRC, Ubuntu USN-8094-1, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."