xhci: Handle TD clearing for multiple streams case
In the Linux kernel, the following vulnerability has been resolved: xhci: Handle TD clearing for multiple streams case When multiple streams are in use, multiple TDs might be in flight when an endpoint is stopped. We need to issue a Set TR Dequeue Pointer for each, to ensure everything is reset properly and the caches cleared. Change the logic so that any N>1 TDs found active for different streams are deferred until after the first one is processed, calling xhci_invalidate_cancelled_tds() again from xhci_handle_cmd_set_deq() to queue another command until we are done with all of them. Also change the error/"should never happen" paths to ensure we at least clear any affected TDs, even if we can't issue a command to clear the hardware cache, and complain loudly with an xhci_warn() if this ever happens. This problem case dates back to commit e9df17eb1408 ("USB: xhci: Correct assumptions about number of rings per endpoint.") early on in the XHCI driver's life, when stream support was first added. It was then identified but not fixed nor made into a warning in commit 674f8438c121 ("xhci: split handling halted endpoints into two steps"), which added a FIXME comment for the problem case (without materially changing the behavior as far as I can tell, though the new logic made the problem more obvious). Then later, in commit 94f339147fc3 ("xhci: Fix failure to give back some cached cancelled URBs."), it was acknowledged again. [Mathias: commit 94f339147fc3 ("xhci: Fix failure to give back some cached cancelled URBs.") was a targeted regression fix to the previously mentioned patch. Users reported issues with usb stuck after unmounting/disconnecting UAS devices. This rolled back the TD clearing of multiple streams to its original state.] Apparently the commit author was aware of the problem (yet still chose to submit it): It was still mentioned as a FIXME, an xhci_dbg() was added to log the problem condition, and the remaining issue was mentioned in the commit description. The choice of making the log type xhci_dbg() for what is, at this point, a completely unhandled and known broken condition is puzzling and unfortunate, as it guarantees that no actual users would see the log in production, thereby making it nigh undebuggable (indeed, even if you turn on DEBUG, the message doesn't really hint at there being a problem at all). It took me *months* of random xHC crashes to finally find a reliable repro and be able to do a deep dive debug session, which could all have been avoided had this unhandled, broken condition been actually reported with a warning, as it should have been as a bug intentionally left in unfixed (never mind that it shouldn't have been left in at all). > Another fix to solve clearing the caches of all stream rings with > cancelled TDs is needed, but not as urgent. 3 years after that statement and 14 years after the original bug was introduced, I think it's finally time to fix it. And maybe next time let's not leave bugs unfixed (that are actually worse than the original bug), and let's actually get people to review kernel commits please. Fixes xHC crashes and IOMMU faults with UAS devices when handling errors/faults. Easiest repro is to use `hdparm` to mark an early sector (e.g. 1024) on a disk as bad, then `cat /dev/sdX > /dev/null` in a loop. At least in the case of JMicron controllers, the read errors end up having to cancel two TDs (for two queued requests to different streams) and the one that didn't get cleared properly ends up faulting the xHC entirely when it tries to access DMA pages that have since been unmapped, referred to by the stale TDs. This normally happens quickly (after two or three loops). After this fix, I left the `cat` in a loop running overnight and experienced no xHC failures, with all read errors recovered properly. Repro'd and tested on an Apple M1 Mac Mini (dwc3 host). On systems without an IOMMU, this bug would instead silently corrupt freed memory, making this a ---truncated---
- Yayın
- 12 Tem 2024
- Güncelleme
- 17 Haz 2026
- EPSS
- %0,3 · 20. yüzdelik
- CWE
- CWE-416
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
31
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 31 / 40 · 7.8 / 10
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,3
CISA SSVC kararı
- Sömürü
- yok
- Otomatikleştirilebilir
- hayır
- Teknik etki
- kısmi
Vulnrichment: CISA'nın karar ağacı girdileri.
Etkilenen sistemler
| Üretici | Ürün | CPE |
|---|---|---|
| linux | linux kernel | cpe:2.3:o:linux:linux_kernel |
Etkilenen sürümler
NVD sürüm aralıkları (katalogdaki ürünler için). Stack’ine sürümle eklersen eşleşme bunlarla yapılır.
- linux linux kernel2.6.35 ve sonrası · 5.15.162 öncesi
- linux linux kernel5.16 ve sonrası · 6.1.95 öncesi
- linux linux kernel6.2 ve sonrası · 6.6.35 öncesi
- linux linux kernel6.7 ve sonrası · 6.9.6 öncesi
- linux linux kernel6.10
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 2.6.35etkilenir
- e9df17eb1408cfafa3d1844bfc7f22c7237b31b8 ve sonrası · 26460c1afa311524f588e288a4941432f0de6228 öncesietkilenir · git
- e9df17eb1408cfafa3d1844bfc7f22c7237b31b8 ve sonrası · 633f72cb6124ecda97b641fbc119340bd88d51a9 öncesietkilenir · git
- e9df17eb1408cfafa3d1844bfc7f22c7237b31b8 ve sonrası · 949be4ec5835e0ccb3e2a8ab0e46179cb5512518 öncesietkilenir · git
- e9df17eb1408cfafa3d1844bfc7f22c7237b31b8 ve sonrası · 61593dc413c3655e4328a351555235bc3089486a öncesietkilenir · git
- e9df17eb1408cfafa3d1844bfc7f22c7237b31b8 ve sonrası · 5ceac4402f5d975e5a01c806438eb4e554771577 öncesietkilenir · git
- 2.6.35 öncesietkilenmez · semver
- 5.15.162 ve sonrası · 5.15.* dahil öncesietkilenmez · semver
- 6.1.95 ve sonrası · 6.1.* dahil öncesietkilenmez · semver
- 6.6.35 ve sonrası · 6.6.* dahil öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| AlmaLinux:9 | bpftool | 7.3.0-427.35.1.el9_4 öncesi | 7.3.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-core | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug-core | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug-devel | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug-devel-matched | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug-modules | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug-modules-core | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-debug-modules-extra | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-devel | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-devel-matched | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-modules | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-modules-core | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-64k-modules-extra | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-abi-stablelists | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-core | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-cross-headers | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-debug | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-debug-core | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-debug-devel | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-debug-devel-matched | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
| AlmaLinux:9 | kernel-debug-modules | 5.14.0-427.35.1.el9_4 öncesi | 5.14.0-427.35.1.el9_4 |
+96
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV89Hemen
- CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV85Hemen
- CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV83Hemen
- CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV77Bu hafta
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV77Bu hafta
- CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV77Bu hafta
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 26460c1afa311524f588e288a4941432f0de6228 | Üretici (CNA) |
| Linux Linux | 5ceac4402f5d975e5a01c806438eb4e554771577 | Üretici (CNA) |
| Linux Linux | 61593dc413c3655e4328a351555235bc3089486a | Üretici (CNA) |
| Linux Linux | 633f72cb6124ecda97b641fbc119340bd88d51a9 | Üretici (CNA) |
| Linux Linux | 949be4ec5835e0ccb3e2a8ab0e46179cb5512518 | Üretici (CNA) |
| almalinux:bpftool | 7.3.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-core | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug-core | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug-devel | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug-devel-matched | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug-modules | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug-modules-core | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-debug-modules-extra | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:kernel-64k-devel | 5.14.0-427.35.1.el9_4 · AlmaLinux:9 | Paket deposu (OSV) |
| debian:linux | 6.1.99-1 · Debian:12 | Paket deposu (OSV) |
| red hat:bpftool-debuginfo | 0:7.3.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debug-debuginfo | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debug-devel | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debug-devel-matched | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debuginfo | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-devel | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-devel-matched | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debug-debuginfo | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debug-devel | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debug-devel-matched | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debuginfo | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debuginfo-common-aarch64 | 0:5.14.0-427.35.1.el9_4 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
+1
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Saldırı koşulları
- Sisteme yerel erişimi olan biri tetikleyebilir.
- Düşük yetkili bir hesap yeterli.
- Kullanıcının bir şey yapması gerekmez.
- Özel bir koşul gerekmez; tekrarlanabilir.
Başarılı olursa
- Gizlilik
- yüksek · veriler okunabilir
- Bütünlük
- yüksek · veri ya da yapılandırma değiştirilebilir
- Erişilebilirlik
- yüksek · hizmet durdurulabilir
- Saldırı vektörü
- Yerel
- Karmaşıklık
- Düşük
- Gereken yetki
- Düşük
- Kullanıcı etkileşimi
- Gerekmez
- Kapsam
- Değişmez
- Gizlilik etkisi
- Yüksek
- Bütünlük etkisi
- Yüksek
- Erişilebilirlik etkisi
- Yüksek
Zayıflık sınıfı (CWE)
CWE-416 · Use After FreeCVSS vektörü
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd-primary
Kök neden
Bir bellek alanı serbest bırakıldıktan sonra ona işaret eden başka bir referans kullanılmaya devam ediyor. Aynı alan o sırada başka bir veri için ayrılmış olabilir.
Hatanın kod karşılığı
CWE-416 sınıfının tamamıBu zafiyet sınıfının temsili örneği. Üreticinin kaynak kodu değildir; hatalı kalıbı ve düzeltmesini gösterir.
Hatalı
free(dev->buf);/* ... başka bir iş parçacığı hâlâ çalışıyor ... */process(dev->buf);Düzeltilmiş
lock(&dev->lock);free(dev->buf);dev->buf = NULL;unlock(&dev->lock);Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
385 binden fazla zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinDeğişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/26460c1afa311524f588e288a4941432f0de6228
- git.kernel.org/stable/c/5ceac4402f5d975e5a01c806438eb4e554771577
- git.kernel.org/stable/c/61593dc413c3655e4328a351555235bc3089486a
- git.kernel.org/stable/c/633f72cb6124ecda97b641fbc119340bd88d51a9
- git.kernel.org/stable/c/949be4ec5835e0ccb3e2a8ab0e46179cb5512518
- lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.