CVE-2026-63874

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: mctp: usb: fix race between urb completion and rx_retry cancellation

It's possible that sequencing between setting ->stopped and cancelling the rx_retry work (in ndo_stop) could leave us with an urb queued:

T1: ndo_stop                  T2: rx_retry_work
------------                  ----------------
                              LD: ->stopped => false
ST: ->stopped <= true
usb_kill_urb()
                              mctp_usb_rx_queue()
                                usb_submit_urb()
cancel_delayed_work_sync()

That urb completion can then re-schedule rx_retry_work.

Strenghen the sequencing between the stop (preventing another requeue) and the cancel by updating both atomically under a new rx lock. After setting ->rx_stopped, and cancelling pending work, we know that the requeue cannot occur, so all that's left is killing any pending urb.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux0791c0327a6e4e7691d6fc5ad334c215de04dcc9 < 9c46f3ee1837f6881cb99a52ffecb2760f11dc73affected
LinuxLinux0791c0327a6e4e7691d6fc5ad334c215de04dcc9 < d90feaa3f74bea8dafb6494631a194c70e547d94affected
LinuxLinux0791c0327a6e4e7691d6fc5ad334c215de04dcc9 < 54665dce982689e2fd99b32e9a0dcc204fda8a51affected
LinuxLinux6.15affected
LinuxLinux0 < 6.15unaffected
LinuxLinux6.18.36 <= 6.18.*unaffected
LinuxLinux7.0.13 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References