CVE-2025-37813 (GCVE-0-2025-37813)
Vulnerability from cvelistv5
Published
2025-05-08 06:26
Modified
2026-08-05 11:57
Summary
In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron workaround This check is performed before prepare_transfer() and prepare_ring(), so enqueue can already point at the final link TRB of a segment. And indeed it will, some 0.4% of times this code is called. Then enqueue + 1 is an invalid pointer. It will crash the kernel right away or load some junk which may look like a link TRB and cause the real link TRB to be replaced with a NOOP. This wouldn't end well. Use a functionally equivalent test which doesn't dereference the pointer and always gives correct result. Something has crashed my machine twice in recent days while playing with an Etron HC, and a control transfer stress test ran for confirmation has just crashed it again. The same test passes with this patch applied.
Impacted products
Vendor Product Version
Linux Linux Version: fbc0a0c7718a6cb1dc5e0811a4f88a2b1deedfa1
Version: 9258c9ed32294ce3a4b58c9d92fc49ba030d35c9
Version: 5e1c67abc9301d05130b7e267c204e7005503b33
Version: 5e1c67abc9301d05130b7e267c204e7005503b33
Version: 4725344ca645a98a9d8e45e25b01a2244de5b8aa
Version: 6.6.66   
Version: 6.12.2   
Version: 6.11.11   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/usb/host/xhci-ring.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "142273a49f2c315eabdbdf5a71c15e479b75ca91",
              "status": "affected",
              "version": "fbc0a0c7718a6cb1dc5e0811a4f88a2b1deedfa1",
              "versionType": "git"
            },
            {
              "lessThan": "bce3055b08e303e28a8751f6073066f5c33a0744",
              "status": "affected",
              "version": "9258c9ed32294ce3a4b58c9d92fc49ba030d35c9",
              "versionType": "git"
            },
            {
              "lessThan": "0624e29c595b05e7a0e6d1c368f0a05799928e30",
              "status": "affected",
              "version": "5e1c67abc9301d05130b7e267c204e7005503b33",
              "versionType": "git"
            },
            {
              "lessThan": "1ea050da5562af9b930d17cbbe9632d30f5df43a",
              "status": "affected",
              "version": "5e1c67abc9301d05130b7e267c204e7005503b33",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4725344ca645a98a9d8e45e25b01a2244de5b8aa",
              "versionType": "git"
            },
            {
              "lessThan": "6.6.89",
              "status": "affected",
              "version": "6.6.66",
              "versionType": "semver"
            },
            {
              "lessThan": "6.12.26",
              "status": "affected",
              "version": "6.12.2",
              "versionType": "semver"
            },
            {
              "lessThan": "6.12",
              "status": "affected",
              "version": "6.11.11",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/usb/host/xhci-ring.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "lessThan": "6.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.89",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.26",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.89",
                  "versionStartIncluding": "6.6.66",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.26",
                  "versionStartIncluding": "6.12.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.5",
                  "versionStartIncluding": "6.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "6.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.11.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix invalid pointer dereference in Etron workaround\n\nThis check is performed before prepare_transfer() and prepare_ring(), so\nenqueue can already point at the final link TRB of a segment. And indeed\nit will, some 0.4% of times this code is called.\n\nThen enqueue + 1 is an invalid pointer. It will crash the kernel right\naway or load some junk which may look like a link TRB and cause the real\nlink TRB to be replaced with a NOOP. This wouldn\u0027t end well.\n\nUse a functionally equivalent test which doesn\u0027t dereference the pointer\nand always gives correct result.\n\nSomething has crashed my machine twice in recent days while playing with\nan Etron HC, and a control transfer stress test ran for confirmation has\njust crashed it again. The same test passes with this patch applied."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable path is entered whenever a control transfer is queued on a SuperSpeed device\u0027s ep0, which an unprivileged local process can drive directly via usbfs ioctls (USBDEVFS_CONTROL/USBDEVFS_SUBMITURB), hidraw feature reports, or ALSA/UVC control APIs on an already-attached device. No network or physical access is needed once any USB3 device is present on the Etron host.\nAC:L - Within the affected configuration the attacker fully controls the trigger \u2014 the enqueue pointer lands on the segment\u0027s final Link TRB on roughly 0.4% of calls, so a short loop of control transfers hits it deterministically in well under a second, exactly as the author\u0027s stress test demonstrated. No memory layout or timing condition outside the attacker\u0027s influence is required.\nPR:L - A basic unprivileged local account suffices, since desktop/kiosk systems grant the seat\u0027s logged-in user access to USB device nodes (usbfs, hidraw, ALSA controls) through udev uaccess rules, and any of those interfaces emit ep0 control transfers. No CAP_SYS_ADMIN or root is required to reach xhci_queue_ctrl_tx().\nUI:N - The attacker issues the control transfers from their own process; no victim action, no mount, and no file-open by another user is involved. Enumeration-driven variants are likewise self-initiated.\nS:U - The out-of-bounds read and the subsequent ring corruption both occur within kernel memory managed by the same security authority; the impact does not cross a VM, IOMMU, or sandbox boundary in the CVSS sense.\nC:H - The out-of-bounds read pulls in contents of an unrelated page adjacent to the DMA segment, and the resulting Link-TRB destruction makes the host controller execute arbitrary post-segment memory as TRBs whose 64-bit buffer pointers can source DMA reads from arbitrary kernel memory, with the data delivered back to userspace through URB completion.\nI:H - The driver overwrites the live Link TRB with a No-Op, corrupting the transfer ring, after which the xHC fetches junk TRBs from outside the ring and can perform DMA writes of device-supplied data to attacker-influenceable addresses \u2014 an arbitrary kernel memory write primitive suitable for control-flow hijacking.\nA:H - The commit states the invalid dereference \"will crash the kernel right away\" on the OOB access; failing that, the corrupted ring wedges the endpoint permanently (\"Tried to move enqueue past ring segment\") and drives the controller off the end of the segment, and the author reproduced machine crashes three times."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:57:42.473Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/142273a49f2c315eabdbdf5a71c15e479b75ca91"
        },
        {
          "url": "https://git.kernel.org/stable/c/bce3055b08e303e28a8751f6073066f5c33a0744"
        },
        {
          "url": "https://git.kernel.org/stable/c/0624e29c595b05e7a0e6d1c368f0a05799928e30"
        },
        {
          "url": "https://git.kernel.org/stable/c/1ea050da5562af9b930d17cbbe9632d30f5df43a"
        }
      ],
      "title": "usb: xhci: Fix invalid pointer dereference in Etron workaround",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-37813",
    "datePublished": "2025-05-08T06:26:10.000Z",
    "dateReserved": "2025-04-16T04:51:23.946Z",
    "dateUpdated": "2026-08-05T11:57:42.473Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…