Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-68288— usb: storage: Fix memory leak in USB bulk transport

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于USB批量传输中存在内存泄漏,可能导致数据泄露。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.20% · P10

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 28

VendorProduct Version RangeStatus
Linux Linux a45b599ad808c3c982fdcdc12b0b8611c2f92824< 83f0241959831586d9b6d47f6bd5d3dec8f43bf0 affected
a45b599ad808c3c982fdcdc12b0b8611c2f92824< 4ba515dfff7eeca369ab85cdbb3f3b231c71720c affected
a45b599ad808c3c982fdcdc12b0b8611c2f92824< 467fec3cefbeb9e3ea80f457da9a5666a71ca0d0 affected
a45b599ad808c3c982fdcdc12b0b8611c2f92824< cb1401b5bcc2feb5b038fc4b512e5968b016e05e affected
a45b599ad808c3c982fdcdc12b0b8611c2f92824< 0f18eac44c5668204bf6eebb01ddb369ac56932b affected
a45b599ad808c3c982fdcdc12b0b8611c2f92824< 5b815ddb3f5560fac35b16de3a2a22d5f81c5993 affected
a45b599ad808c3c982fdcdc12b0b8611c2f92824< 41e99fe2005182139b1058db71f0d241f8f0078c affected
582802e7c617cfb07cc15f280c128e6decbc57b8 affected
… +20 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-68288

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
usb: storage: Fix memory leak in USB bulk transport
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: storage: Fix memory leak in USB bulk transport A kernel memory leak was identified by the 'ioctl_sg01' test from Linux Test Project (LTP). The following bytes were mainly observed: 0x53425355. When USB storage devices incorrectly skip the data phase with status data, the code extracts/validates the CSW from the sg buffer, but fails to clear it afterwards. This leaves status protocol data in srb's transfer buffer, such as the US_BULK_CS_SIGN 'USBS' signature observed here. Thus, this can lead to USB protocols leaks to user space through SCSI generic (/dev/sg*) interfaces, such as the one seen here when the LTP test requested 512 KiB. Fix the leak by zeroing the CSW data in srb's transfer buffer immediately after the validation of devices that skip data phase. Note: Differently from CVE-2018-1000204, which fixed a big leak by zero- ing pages at allocation time, this leak occurs after allocation, when USB protocol data is written to already-allocated sg pages.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于USB批量传输中存在内存泄漏,可能导致数据泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux a45b599ad808c3c982fdcdc12b0b8611c2f92824 ~ 83f0241959831586d9b6d47f6bd5d3dec8f43bf0 -
Linux Linux 4.17 -

II. Public POCs for CVE-2025-68288

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-68288

登录查看更多情报信息。

Other References for CVE-2025-68288 (7)

Same Patch Batch · Linux · 2025-12-16 · 157 CVEs total

CVE-2025-68192 9.8 CRITICAL net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
CVE-2025-68301 9.8 CRITICAL net: atlantic: fix fragment overflow handling in RX path
CVE-2025-40350 9.8 CRITICAL net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ
CVE-2025-68284 9.8 CRITICAL libceph: prevent potential out-of-bounds writes in handle_auth_session_key()
CVE-2025-68285 9.8 CRITICAL libceph: fix potential use-after-free in have_mon_and_osd_map()
CVE-2025-68263 9.8 CRITICAL ksmbd: ipc: fix use-after-free in ipc_msg_send_request
CVE-2025-68315 9.8 CRITICAL f2fs: fix to detect potential corrupted nid in free_nid_list
CVE-2025-68226 8.8 HIGH smb: client: fix incomplete backport in cfids_invalidation_worker()
CVE-2025-68304 8.8 HIGH Bluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-68255 8.8 HIGH staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
CVE-2025-68256 8.8 HIGH staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
CVE-2025-40362 8.8 HIGH ceph: fix multifs mds auth caps issue
CVE-2025-68314 8.8 HIGH drm/msm: make sure last_fence is always updated
CVE-2025-68250 8.2 HIGH hung_task: fix warnings caused by unaligned lock pointers
CVE-2025-68175 7.8 HIGH media: nxp: imx8-isi: Fix streaming cleanup on release
CVE-2025-68171 7.8 HIGH x86/fpu: Ensure XFD state on signal delivery
CVE-2025-68179 7.8 HIGH s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP
CVE-2025-68260 7.8 HIGH rust_binder: fix race condition on death_list
CVE-2025-68303 7.8 HIGH platform/x86: intel: punit_ipc: fix memory corruption
CVE-2025-68234 7.8 HIGH io_uring/cmd_net: fix wrong argument types for skb_queue_splice()

Showing top 20 of 157 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-68288

No comments yet


Leave a comment