cbcvebase.
CVE-2025-68331
published 2025-12-22

CVE-2025-68331: In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data…

PriorityP424high7.8
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer When a UAS device is unplugged during data transfer, there is a probability of a system panic occurring. The root cause is an access to an invalid memory address during URB callback handling. Specifically, this happens when the dma_direct_unmap_sg() function is called within the usb_hcd_unmap_urb_for_dma() interface, but the sg->dma_address field is 0 and the sg data structure has already been freed. The SCSI driver sends transfer commands by invoking uas_queuecommand_lck() in uas.c, using the uas_submit_urbs() function to submit requests to USB. Within the uas_submit_urbs() implementation, three URBs (sense_urb, data_urb, and cmd_urb) are sequentially submitted. Device removal may occur at any point during uas_submit_urbs execution, which may result in URB submission failure. However, some URBs might have been successfully submitted before the failure, and uas_submit_urbs will return the -ENODEV error code in this case. The current error handling directly calls scsi_done(). In the SCSI driver, this eventually triggers scsi_complete() to invoke scsi_end_request() for releasing the sgtable. The successfully submitted URBs, when being unlinked to giveback, call usb_hcd_unmap_urb_for_dma() in hcd.c, leading to exceptions during sg unmapping operations since the sg data structure has already been freed. This patch modifies the error condition check in the uas_submit_urbs() function. When a UAS device is removed but one or more URBs have already been successfully submitted to USB, it avoids immediately invoking scsi_done() and save the cmnd to devinfo->cmnd array. If the successfully submitted URBs is completed before devinfo->resetting being set, then the scsi_done() function will be called within uas_try_complete() after all pending URB operations are finalized. Otherwise, the scsi_done() function will be c

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < 6289fc489e94c9beb6be2b502ccc263663733d726289fc489e94c9beb6be2b502ccc263663733d72
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < 66ac05e7b0d6bbd1bee9fcf729e20fd4cce86d1766ac05e7b0d6bbd1bee9fcf729e20fd4cce86d17
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < 75f8e2643085db4f7e136fc6b368eb114dd80a6475f8e2643085db4f7e136fc6b368eb114dd80a64
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < e3a55221f4de080cb7a91ba10f01c4f708603f8de3a55221f4de080cb7a91ba10f01c4f708603f8d
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < 2b90a8131c83f6f2be69397d2b7d14d217d95d2f2b90a8131c83f6f2be69397d2b7d14d217d95d2f
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < 426edbfc88b22601ea34a441a469092e7b301c52426edbfc88b22601ea34a441a469092e7b301c52
linuxlinux>= eb2a86ae8c544be0ab04aa8169390c0669bc7148 < 26d56a9fcb2014b99e654127960aa0a48a391e3c26d56a9fcb2014b99e654127960aa0a48a391e3c
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.10.0 < 5.10.2475.10.247
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.2.0 < 6.6.1196.6.119
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-azure-5.15

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.