CVE-2025-68324

Updated on 18 Dec 2025

Severity

7.1 High severity

Details

CVSS score
7.1

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item ‘imm_tq’ is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI host adapter is detached through imm_detach(), the imm_struct device instance is deallocated. However, the delayed work might still be pending or executing when imm_detach() is called, leading to use-after-free bugs when the work function imm_interrupt() accesses the already freed imm_struct memory. The race condition can occur as follows: CPU 0(detach thread) | CPU 1 | imm_queuecommand() | imm_queuecommand_lck() imm_detach() | schedule_delayed_work() kfree(dev) //FREE | imm_interrupt() | dev = container_of(…) //USE dev-> //USE Add disable_delayed_work_sync() in imm_detach() to guarantee proper cancellation of the delayed work item before imm_struct is deallocated. A flaw was found in the Linux kernel. A local user could trigger a use-after-free vulnerability in the Intelligent Multi-Master (IMM) parallel port SCSI host adapter. This occurs due to a race condition where a delayed work item might still be active when the adapter is detached, leading to attempts to access freed memory. Successful exploitation can result in a denial of service.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Will Not Fix