CVE-2026-74680: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026082231-CVE-2026-74680-526a@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() If cxacru_cm() encounters an error while submitting or waiting for snd_urb, it aborts and returns the error without killing the already submitted rcv_urb. This leaves the rcv_urb active. When this happens during initialization (e.g., in cxacru_atm_start()), the driver may ignore the error and proceed to call cxacru_poll_status(), which invokes cxacru_cm() again. Attempting to submit the still-active rcv_urb triggers a warning in usb_submit_urb(): cxacru 1-1:1.0: send of cm 0x84 failed (-104) ATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104 ------------[ cut here ]------------ URB ffff88812658d200 submitted while active WARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0 drivers/usb/core/urb.c:379 ... Call Trace: <TASK> cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631 cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline] cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828 cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814 usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927 usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178 cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370 ... To fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts early. We can safely call usb_kill_urb() on rcv_urb in the error path, as it is safe to call even if the URB is not active (e.g., if it failed to submit in the first place, or if it already completed). The Linux kernel CVE team has assigned CVE-2026-74680 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 5.10.265 with commit 6133b461058316e3ccba7331f974d110d4c08b23 Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 5.15.216 with commit 61093d7f1144f6a15bac505df35e5f535ade2ac1 Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 6.1.183 with commit 645d98dbccdbfdbf0129f48822af7183492de091 Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 6.6.152 with commit 993f7677949e3d72e360e86eed1f41c2511f75ed Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 6.12.104 with commit 939b6a41f681aea52af678053072ee443068e93e Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 6.18.45 with commit 2f73a065791d2a8e3f0bdf29248e33600359e865 Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 7.1.9 with commit 0af047703dbed8224552587ed436f14a24371b46 Issue introduced in 2.6.13 with commit 1b0e614652344a2d39eb336f3dc07651782883bf and fixed in 7.2 with commit c2f811314be351d86b6ab41e9297ae80d8da6f86 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74680 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/usb/atm/cxacru.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6133b461058316e3ccba7331f974d110d4c08b23 https://git.kernel.org/stable/c/61093d7f1144f6a15bac505df35e5f535ade2ac1 https://git.kernel.org/stable/c/645d98dbccdbfdbf0129f48822af7183492de091 https://git.kernel.org/stable/c/993f7677949e3d72e360e86eed1f41c2511f75ed https://git.kernel.org/stable/c/939b6a41f681aea52af678053072ee443068e93e https://git.kernel.org/stable/c/2f73a065791d2a8e3f0bdf29248e33600359e865 https://git.kernel.org/stable/c/0af047703dbed8224552587ed436f14a24371b46 https://git.kernel.org/stable/c/c2f811314be351d86b6ab41e9297ae80d8da6f86