SB2025121650 - Memory leak in Linux kernel usb storage driver
Published: December 16, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-68288)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the usb_stor_Bulk_transport() function in drivers/usb/storage/transport.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0f18eac44c5668204bf6eebb01ddb369ac56932b
- https://git.kernel.org/stable/c/41e99fe2005182139b1058db71f0d241f8f0078c
- https://git.kernel.org/stable/c/467fec3cefbeb9e3ea80f457da9a5666a71ca0d0
- https://git.kernel.org/stable/c/4ba515dfff7eeca369ab85cdbb3f3b231c71720c
- https://git.kernel.org/stable/c/5b815ddb3f5560fac35b16de3a2a22d5f81c5993
- https://git.kernel.org/stable/c/83f0241959831586d9b6d47f6bd5d3dec8f43bf0
- https://git.kernel.org/stable/c/cb1401b5bcc2feb5b038fc4b512e5968b016e05e