-
CVE-2025-68342
- EPSS 0.03%
- Veröffentlicht 23.12.2025 13:58:27
- Zuletzt bearbeitet 23.12.2025 14:51:52
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data The URB received in gs_usb_receive_bulk_callback() contains a struct gs_host_frame. The length of the data after the header depends on the gs_host_frame hf::flags and the active device features (e.g. time stamping). Introduce a new function gs_usb_get_minimum_length() and check that we have at least received the required amount of data before accessing it. Only copy the data to that skb that has actually been received. [mkl: rename gs_usb_get_minimum_length() -> +gs_usb_get_minimum_rx_length()]
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version <
4ffac725154cf6a253f5e6aa0c8946232b6a0af5
Version
d08e973a77d128b25e01a08c34d89593fdf222da
Status
affected
Version <
ad55004a3cb5b41ef78aa6c09e7bc5a489ba652b
Version
d08e973a77d128b25e01a08c34d89593fdf222da
Status
affected
Version <
fb0c7c77a7ae3a2c3404b7d0173b8739a754b513
Version
d08e973a77d128b25e01a08c34d89593fdf222da
Status
affected
Version <
395d988f93861101ec89d0dd9e3b876ae9392a5b
Version
d08e973a77d128b25e01a08c34d89593fdf222da
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.16
Status
affected
Version <
3.16
Version
0
Status
unaffected
Version <=
6.6.*
Version
6.6.119
Status
unaffected
Version <=
6.12.*
Version
6.12.61
Status
unaffected
Version <=
6.17.*
Version
6.17.11
Status
unaffected
Version <=
*
Version
6.18
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.064 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|