SB2025121664 - Use-after-free in Linux kernel usb dwc3 driver
Published: December 16, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-68287)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the dwc3_gadget_giveback() function in drivers/usb/dwc3/gadget.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/467add9db13219101f14b6cc5477998b4aaa5fe2
- https://git.kernel.org/stable/c/47de14d741cc4057046c9e2f33df1f7828254e6c
- https://git.kernel.org/stable/c/67192e8cb7f941b5bba91e4bb290683576ce1607
- https://git.kernel.org/stable/c/7cfb62888eba292fa35cd9ddbd28ce595f60e139
- https://git.kernel.org/stable/c/afc0e34f161ce61ad351303c46eb57bd44b8b090
- https://git.kernel.org/stable/c/e4037689a366743c4233966f0e74bc455820d316
- https://git.kernel.org/stable/c/fa5eaf701e576880070b60922200557ae4aa54e1