Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-68750

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/12/2025
Última modificación:
24/12/2025

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: potential integer overflow in usbg_make_tpg()<br /> <br /> The variable tpgt in usbg_make_tpg() is defined as unsigned long and is<br /> assigned to tpgt-&gt;tport_tpgt, which is defined as u16. This may cause an<br /> integer overflow when tpgt is greater than USHRT_MAX (65535). I<br /> haven&amp;#39;t tried to trigger it myself, but it is possible to trigger it<br /> by calling usbg_make_tpg() with a large value for tpgt.<br /> <br /> I modified the type of tpgt to match tpgt-&gt;tport_tpgt and adjusted the<br /> relevant code accordingly.<br /> <br /> This patch is similar to commit 59c816c1f24d ("vhost/scsi: potential<br /> memory corruption").

Impacto