Wind River Support Network

HomeDefectsLIN1024-7888
Acknowledged

LIN1024-7888 : Security Advisory - linux - CVE-2025-21838

Created: Mar 9, 2025    Updated: Mar 13, 2025
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: core: flush gadget workqueue after device removal

device_del() can lead to new work being scheduled in gadget->work
workqueue. This is observed, for example, with the dwc3 driver with the
following call stack:
  device_del()
    gadget_unbind_driver()
      usb_gadget_disconnect_locked()
        dwc3_gadget_pullup()
	  dwc3_gadget_soft_disconnect()
	    usb_gadget_set_state()
	      schedule_work(&gadget->work)

Move flush_work() after device_del() to ensure the workqueue is cleaned
up.

CREATE(Triage):(User=admin) CVE-2025-21838 (https://nvd.nist.gov/vuln/detail/CVE-2025-21838)
Live chat
Online