cbcvebase.
CVE-2025-23151
published 2025-05-01

CVE-2025-23151: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix race between unprepare and queue_buf A client driver may use…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix race between unprepare and queue_buf A client driver may use mhi_unprepare_from_transfer() to quiesce incoming data during the client driver's tear down. The client driver might also be processing data at the same time, resulting in a call to mhi_queue_buf() which will invoke mhi_gen_tre(). If mhi_gen_tre() runs after mhi_unprepare_from_transfer() has torn down the channel, a panic will occur due to an invalid dereference leading to a page fault. This occurs because mhi_gen_tre() does not verify the channel state after locking it. Fix this by having mhi_gen_tre() confirm the channel state is valid, or return error to avoid accessing deinitialized data. [mani: added stable tag]

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 0b093176fd0967a5f56e2c86b0d48247f6c0fa0f < 3e7ecf181cbdde9753204ada3883ca1704d8702b3e7ecf181cbdde9753204ada3883ca1704d8702b
linuxlinux>= 176ed1727badd2fad2158e2b214dcbc24f4be7a1 < 899d0353ea69681f474b6bc9de32c663b89672da899d0353ea69681f474b6bc9de32c663b89672da
linuxlinux>= 5.15.149 < 5.15.1815.15.181
linuxlinux>= 6.1.76 < 6.1.1356.1.135
linuxlinux>= 6.6.15 < 6.6.886.6.88
linuxlinux>= 6.7.3 < 6.86.8
linuxlinux>= b89b6a863dd53bc70d8e52d50f9cfaef8ef5e9c9 < a77955f7704b2a00385e232cbcc1cb06b5c7a425a77955f7704b2a00385e232cbcc1cb06b5c7a425
linuxlinux>= b89b6a863dd53bc70d8e52d50f9cfaef8ef5e9c9 < 178e5657c8fd285125cc6743a81b513bce099760178e5657c8fd285125cc6743a81b513bce099760
linuxlinux>= b89b6a863dd53bc70d8e52d50f9cfaef8ef5e9c9 < ee1fce83ed56450087309b9b74ad9bcb2b010fa6ee1fce83ed56450087309b9b74ad9bcb2b010fa6
linuxlinux>= b89b6a863dd53bc70d8e52d50f9cfaef8ef5e9c9 < 0686a818d77a431fc3ba2fab4b46bbb04e8c93800686a818d77a431fc3ba2fab4b46bbb04e8c9380
linuxlinux>= ce16274a6b8d1483d0d8383272deb2bfd1b577ca < 5f084993c90d9d0b4a52a349ede5120f992a7ca15f084993c90d9d0b4a52a349ede5120f992a7ca1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.15.149 < 5.15.1815.15.181
linuxlinux_kernel>= 6.1.76 < 6.1.1356.1.135
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.