PT-2025-42267 · Linux+5 · Linux Kernel+5

Published

2025-10-15

·

Updated

2026-05-26

·

CVE-2025-39993

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-rc1-syzkaller
Description The iMON driver does not properly manage USB device references during disconnection, leading to a potential use-after-free condition. Specifically, the usb device reference count is decremented unconditionally in imon disconnect without considering active users of the device. This can occur if operations like vfd write are in progress when the device is disconnected, resulting in a use-after-free of the usb device pointer. The issue arises because the fields usbdev intf0 and usbdev intf1 are not protected by a user counter. The vulnerability can be triggered when send packet() or other operations attempt to access the usbdev intf0 pipe after the device has been disconnected.
Recommendations Update to a version beyond 6.0.0-rc1-syzkaller.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALSA-2026:0443
ALSA-2026:0444
BDU:2026-02770
CVE-2025-39993
DLA-4379-1
DLA-4404-1
DSA-6053-1
ECHO-146F-4F03-6E49
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2551
OESA-2025-2552
OESA-2025-2556
OESA-2025-2632
OESA-2025-2636
OPENSUSE-SU-2025:15671-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
RHSA-2026:0443
RHSA-2026:0444
RHSA-2026:0533
RHSA-2026:1442
RHSA-2026:1445
RHSA-2026:1512
RHSA-2026:3634
RHSA-2026:3685
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1
USN-7921-1
USN-7921-2
USN-7922-1
USN-7922-2
USN-7922-3
USN-7922-4
USN-7922-5
USN-7928-1
USN-7928-2
USN-7928-3
USN-7928-4
USN-7928-5
USN-7931-1
USN-7931-2
USN-7931-3
USN-7931-4
USN-7931-5
USN-7934-1
USN-7935-1
USN-7936-1
USN-7938-1
USN-7939-1
USN-7939-2
USN-7940-1
USN-7940-2
USN-7987-1
USN-7987-2
USN-7988-1
USN-7988-2
USN-7988-3
USN-7988-4
USN-7988-5

Affected Products

Debian
Linuxmint
Linux Kernel
Rocky Linux
Suse
Ubuntu