Back to overview

CVE-2026-63874

Description
In the Linux kernel, the following vulnerability has been resolved: net: mctp: usb: fix race between urb completion and rx_retry cancellation It's possible that sequencing between setting ->stopped and cancelling the rx_retry work (in ndo_stop) could leave us with an urb queued: T1: ndo_stop T2: rx_retry_work ------------ ---------------- LD: ->stopped => false ST: ->stopped <= true usb_kill_urb() mctp_usb_rx_queue() usb_submit_urb() cancel_delayed_work_sync() That urb completion can then re-schedule rx_retry_work. Strenghen the sequencing between the stop (preventing another requeue) and the cancel by updating both atomically under a new rx lock. After setting ->rx_stopped, and cancelling pending work, we know that the requeue cannot occur, so all that's left is killing any pending urb.

Metadata

CVE ID
CVE-2026-63874
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:18 UTC
Last updated
2026-07-19 14:18 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 0791c0327a6e4e7691d6fc5ad334c215de04dcc9 < 9c46f3ee1837f6881cb99a52ffecb2760f11dc73, 0791c0327a6e4e7691d6fc5ad334c215de04dcc9 < d90feaa3f74bea8dafb6494631a194c70e547d94, 0791c0327a6e4e7691d6fc5ad334c215de04dcc9 < 54665dce982689e2fd99b32e9a0dcc204fda8a51
Linux Linux 6.15, 0 < 6.15, 6.18.36 ≤ 6.18.*, 7.0.13 ≤ 7.0.* …
Back to overview