#VU120547 Integer overflow in Linux kernel - CVE-2025-68750
Published: December 26, 2025
Vulnerability identifier: #VU120547
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-68750
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer overflow within the usbg_make_tpg() function in drivers/usb/gadget/function/f_tcm.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/0861b9cb2ff519b7c5a3b1dd52a343e18c4efb24
- https://git.kernel.org/stable/c/153874010354d050f62f8ae25cbb960c17633dc5
- https://git.kernel.org/stable/c/358d5ba08f1609c34a054aed88c431844d09705a
- https://git.kernel.org/stable/c/603a83e5fee38a950bfcfb2f36449311fa00a474
- https://git.kernel.org/stable/c/620a5e1e84a3a7004270703a118d33eeb1c0f368
- https://git.kernel.org/stable/c/6722e080b5b39ab7471386c73d0c1b39572f943c
- https://git.kernel.org/stable/c/6f77e344515b5258edb3988188311464209b1c7c
- https://git.kernel.org/stable/c/a33f507f36d5881f602dab581ab0f8d22b49762c