In the Linux kernel, the following vulnerability has been resolved:
most: usb: fix double free on late probe failure
The MOST subsystem has a non-standard registration function which frees
the interface on registration failures and on deregistration.
This unsurprisingly leads to bugs in the MOST drivers, and a couple of
recent changes turned a reference underflow and use-after-free in the
USB driver into several double free and a use-after-free on late probe
failures.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-16 16:16
Updated : 2026-06-17 09:58
NVD link : CVE-2025-68290
Mitre link : CVE-2025-68290
CVE.ORG link : CVE-2025-68290
JSON object : View
Products Affected
No product.
CWE
No CWE.
