#VU120134 Resource management error in Linux kernel - CVE-2025-68312
Published: December 16, 2025
Vulnerability identifier: #VU120134
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-68312
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the function in drivers/net/usb/usbnet.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/285d4b953f2ca03c358f986718dd89ee9bde632e
- https://git.kernel.org/stable/c/2ce1de32e05445d77fc056f6ff8339cfb78a5f84
- https://git.kernel.org/stable/c/3a10619fdefd3051aeb14860e4d4335529b4e94d
- https://git.kernel.org/stable/c/420c84c330d1688b8c764479e5738bbdbf0a33de
- https://git.kernel.org/stable/c/43005002b60ef3424719ecda16d124714b45da3b
- https://git.kernel.org/stable/c/5158fb8da162e3982940f30cd01ed77bdf42c6fc
- https://git.kernel.org/stable/c/88a38b135d69f5db9024ff6527232f1b51be8915
- https://git.kernel.org/stable/c/9a579d6a39513069d298eee70770bbac8a148565