CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37812: usb: cdns3: Fix deadlock when using NCM gadget

Description

In the Linux kernel, the following vulnerability has been resolved:

usb: cdns3: Fix deadlock when using NCM gadget

The cdns3 driver has the same NCM deadlock as fixed in cdnsp by commit
58f2fcb3a845 ("usb: cdnsp: Fix deadlock issue during using NCM gadget").

Under PREEMPT_RT the deadlock can be readily triggered by heavy network
traffic, for example using "iperf --bidir" over NCM ethernet link.

The deadlock occurs because the threaded interrupt handler gets
preempted by a softirq, but both are protected by the same spinlock.
Prevent deadlock by disabling softirq during threaded irq handler.

Classification

CVE ID: CVE-2025-37812

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 7.6% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37812
https://git.kernel.org/stable/c/eebfb64c624fc738b669100173344fb441c5e719
https://git.kernel.org/stable/c/59a760e4796a3cd88d8b9d7706e0a638de677751
https://git.kernel.org/stable/c/b96239582531775f2fdcb14de29bdb6870fd4c8c
https://git.kernel.org/stable/c/c27db84ed44e50ff90d9e3a2a25fae2e0a0fa015
https://git.kernel.org/stable/c/48a62deb857f0694f611949015e70ad194d97159
https://git.kernel.org/stable/c/74cd6e408a4c010e404832f0e4609d29bf1d0c41
https://git.kernel.org/stable/c/09e90a9689a4aac7a2f726dc2aa472b0b37937b7
https://git.kernel.org/stable/c/a1059896f2bfdcebcdc7153c3be2307ea319501f

Timeline