GHSA-4gv8-vfvf-62f2HighCVSS 7.8

In the Linux kernel, the following vulnerability has been resolved: net: mctp: usb: fix race...

Published
July 19, 2026
Last Modified
July 20, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

net: mctp: usb: fix race between urb completion and rx_retry cancellation

It's possible that sequencing between setting ->stopped and cancelling the rx_retry work (in ndo_stop) could leave us with an urb queued:

T1: ndo_stop                  T2: rx_retry_work
------------                  ----------------
                              LD: ->stopped => false
ST: ->stopped <= true
usb_kill_urb()
                              mctp_usb_rx_queue()
                                usb_submit_urb()
cancel_delayed_work_sync()

That urb completion can then re-schedule rx_retry_work.

Strenghen the sequencing between the stop (preventing another requeue) and the cancel by updating both atomically under a new rx lock. After setting ->rx_stopped, and cancelling pending work, we know that the requeue cannot occur, so all that's left is killing any pending urb.

🔗 References (5)