CVE-2025-68323: usb: typec: ucsi: fix use-after-free caused by uec->work

Published Dec 18, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: fix use-after-free caused by uec->work

The delayed work uec->work is scheduled in gaokunucsiprobe() but never properly canceled in gaokunucsiremove(). This creates use-after-free scenarios where the ucsi and gaokunucsi structure are freed after ucsidestroy() completes execution, while the gaokunucsiregisterworker() might be either currently executing or still pending in the work queue. The already-freed gaokunucsi or ucsi structure may then be accessed.

Furthermore, the race window is 3 seconds, which is sufficiently long to make this bug easily reproducible. The following is the trace captured by KASAN:

================================================================== BUG: KASAN: slab-use-after-free in runtimers+0x5ec/0x630 Write of size 8 at addr ffff00000ec28cc8 by task swapper/0/0 ... Call trace: showstack+0x18/0x24 (C) dumpstacklvl+0x78/0x90 printreport+0x114/0x580 kasanreport+0xa4/0xf0 asanreportstore8noabort+0x20/0x2c runtimers+0x5ec/0x630 runtimersoftirq+0xe8/0x1cc handlesoftirqs+0x294/0x720 dosoftirq+0x14/0x20 dosoftirq+0x10/0x1c callonirqstack+0x30/0x48 dosoftirqownstack+0x1c/0x28 irqexitrcu+0x27c/0x364 irqexitrcu+0x10/0x1c el1interrupt+0x40/0x60 el1h64irqhandler+0x18/0x24 el1h64irq+0x6c/0x70 archlocalirqenable+0x4/0x8 (P) doidle+0x334/0x458 cpustartupentry+0x60/0x70 restinit+0x158/0x174 startkernel+0x2f8/0x394 primaryswitched+0x8c/0x94

Allocated by task 72 on cpu 0 at 27.510341s: kasansavestack+0x2c/0x54 kasansavetrack+0x24/0x5c kasansaveallocinfo+0x40/0x54 kasankmalloc+0xa0/0xb8 kmallocnodetrackcallernoprof+0x1c0/0x588 devmkmalloc+0x7c/0x1c8 gaokunucsiprobe+0xa0/0x840 auxiliarybusprobe+0x94/0xf8 reallyprobe+0x17c/0x5b8 driverprobedevice+0x158/0x2c4 driverprobedevice+0x10c/0x264 deviceattachdriver+0x168/0x2d0 busforeachdrv+0x100/0x188 deviceattach+0x174/0x368 deviceinitialprobe+0x14/0x20 busprobedevice+0x120/0x150 deviceadd+0xb3c/0x10fc auxiliarydeviceadd+0x88/0x130 ...

Freed by task 73 on cpu 1 at 28.910627s: kasansavestack+0x2c/0x54 kasansavetrack+0x24/0x5c kasansavefreeinfo+0x4c/0x74 kasanslabfree+0x60/0x8c kfree+0xd4/0x410 devresreleaseall+0x140/0x1f0 deviceunbindcleanup+0x20/0x190 devicereleasedriverinternal+0x344/0x460 devicereleasedriver+0x18/0x24 busremovedevice+0x198/0x274 devicedel+0x310/0xa84 ...

The buggy address belongs to the object at ffff00000ec28c00 which belongs to the cache kmalloc-512 of size 512 The buggy address is located 200 bytes inside of freed 512-byte region The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4ec28 head: order:2 mapcount:0 entiremapcount:0 nrpagesmapped:0 pincount:0 flags: 0x3fffe0000000040(head|node=0|zone=0|lastcpupid=0x1ffff) pagetype: f5(slab) raw: 03fffe0000000040 ffff000008801c80 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 head: 03fffe0000000040 ffff000008801c80 dead000000000122 0000000000000000 head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 head: 03fffe0000000002 fffffdffc03b0a01 00000000ffffffff 00000000ffffffff head: ffffffffffffffff 0000000000000000 00000000ffffffff 0000000000000004 page dumped because: kasan: bad access detected

Memory state around the buggy address: ffff00000ec28b80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff00000ec28c00: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff00000ec28c80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff00000ec28d00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff00000ec28d80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ================================================================ ---truncated---

Affected Software

1 affected component
linux-kernel

Event History

Dec 18, 2025
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Data Sourced
via NVD·03:16 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2025-68323?

CVE-2025-68323 is classified as a high-severity vulnerability due to its potential to cause use-after-free scenarios in the Linux kernel.

2

How do I fix CVE-2025-68323?

To fix CVE-2025-68323, update to the latest version of the Linux kernel where this vulnerability has been patched.

3

What are the risks associated with CVE-2025-68323?

The risks include potential system crashes or arbitrary code execution due to the use-after-free condition.

4

Which versions of the Linux kernel are affected by CVE-2025-68323?

CVE-2025-68323 affects certain versions of the Linux kernel that utilize the UCSI subsystem.

5

What components are involved in CVE-2025-68323?

CVE-2025-68323 involves the USB Type-C and UCSI components of the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203