CVE-2025-68327
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68327 is a vulnerability in the Linux kernel's Renesas USBHS (USB High-Speed) driver that causes a synchronous external abort when unbinding USB gadget modules on Renesas RZ/G3S SoC devices. The flaw was published on December 22, 2025, and affects the Linux kernel as shipped in distributions including Ubuntu and SUSE, as well as Microsoft's Azure Linux 3 kernel (azl3_kernel prior to 6.6.117.1-1). It carries a CVSS v3.1 base score of 4.7 (Medium) (Red Hat CVE, Microsoft MSRC).

Technical details

The root cause is a use-after-clock-disable condition (related to CWE-362, improper synchronization) in the renesas_usbhs kernel driver: when a USB gadget is configured and then unbound via the platform driver's unbind interface, the driver attempts to access IP registers (specifically via usbhs_sys_function_pullup) after the USBHS clocks have already been disabled during the remove sequence, triggering a synchronous external abort (Red Hat CVE). The abort occurs because the clock gating cuts off register access, and the driver's teardown order does not ensure clocks remain active until all register accesses are complete. The fix repositions the IP clock disable to the very end of the remove process, ensuring no register accesses occur after clocks are stopped. Exploitation requires local access and the ability to load USB gadget modules and execute the unbind operation.

Impact

Successful triggering of this vulnerability causes a synchronous external abort on affected Renesas RZ/G3S SoC systems, resulting in a kernel panic or system crash and a complete loss of availability for the affected device (Red Hat CVE). There is no confidentiality or integrity impact — the vulnerability is purely an availability issue. The scope is limited to the local system running the affected kernel on Renesas RZ/G3S hardware; lateral movement or data exfiltration are not applicable.

Mitigation and workarounds

The primary remediation is to update to a patched Linux kernel version. Patches have been committed to the stable kernel tree (commits 9d86bc8b188a, 230b1bc1310e, 26838f147aea, aa658a6d5ac2). Distribution-specific updates include Ubuntu security notices USN-8094-1 through USN-8094-5 and SUSE kernel updates (Ubuntu USN-8094-1, Ubuntu USN-8094-5). Microsoft's Azure Linux 3 kernel was patched in version 6.6.117.1-1 (Microsoft MSRC). As a workaround, avoid performing USB gadget module unbinding on affected Renesas RZ/G3S SoC devices until the kernel is updated.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management