Description
In the Linux kernel, the following vulnerability has been resolved: usbnet:fix NPE during rx_complete Missing usbnet_going_away Check in Critical Path. The usb_submit_urb function lacks a usbnet_going_away validation, whereas __usbnet_queue_skb includes this check. This inconsistency creates a race condition where: A URB request may succeed, but the corresponding SKB data fails to be queued. Subsequent processes: (e.g., rx_complete → defer_bh → __skb_unlink(skb, list)) attempt to access skb->next, triggering a NULL pointer dereference (Kernel Panic).
Product status
b80aacfea6e8d6ed6e430aa13922d6ccf044415a (git) before 95789c2f94fd29dce8759f9766baa333f749287c
869caa8de8cb94514df704ccbe0b024fda4b9398 (git) before 0f10f83acfd619e13c64d6705908dfd792f19544
1e44ee6cdd123d6cfe78b4a94e1572e23bbb58ce (git) before acacd48a37b52fc95f621765762c04152b58d642
04e906839a053f092ef53f4fb2d610983412b904 (git) before d689645cd1594ea1d13cb0c404f8ad1011353e0e
04e906839a053f092ef53f4fb2d610983412b904 (git) before 0c30988588b28393e3e8873d5654f910e86391ba
04e906839a053f092ef53f4fb2d610983412b904 (git) before fd9ee3f0d6a53844f65efde581c91bbb0ff749ac
04e906839a053f092ef53f4fb2d610983412b904 (git) before 51de3600093429e3b712e5f091d767babc5dd6df
ca124236cd14e61610f56df9a8f81376a1ffe660 (git)
54671d731f4977fb3c0c26f2840655b5204e4437 (git)
5.15.168 (semver) before 5.15.180
6.1.113 (semver) before 6.1.134
6.6.54 (semver) before 6.6.87
6.10.13 (semver) before 6.11
6.11.2 (semver) before 6.12
6.12
Any version before 6.12
5.15.180 (semver)
6.1.134 (semver)
6.6.87 (semver)
6.12.23 (semver)
6.13.11 (semver)
6.14.2 (semver)
6.15 (original_commit_for_fix)
References
lists.debian.org/debian-lts-announce/2025/05/msg00045.html
git.kernel.org/...c/95789c2f94fd29dce8759f9766baa333f749287c
git.kernel.org/...c/0f10f83acfd619e13c64d6705908dfd792f19544
git.kernel.org/...c/acacd48a37b52fc95f621765762c04152b58d642
git.kernel.org/...c/d689645cd1594ea1d13cb0c404f8ad1011353e0e
git.kernel.org/...c/0c30988588b28393e3e8873d5654f910e86391ba
git.kernel.org/...c/fd9ee3f0d6a53844f65efde581c91bbb0ff749ac
git.kernel.org/...c/51de3600093429e3b712e5f091d767babc5dd6df