Executive brief
A vulnerability in the Linux kernel's USB hub driver could allow a specially crafted, non-compliant USB device to crash the system. By presenting more than one configuration or interface—which violates the USB 2.0 specification—the device triggers a memory error (NULL pointer dereference) during the initialization process. This results in a system crash (kernel oops), impacting the availability of the affected machine.
Technical details
A NULL pointer dereference exists in the Linux kernel's USB hub driver within the hub_probe function. The vulnerability is triggered when a USB device provides multiple configurations or interfaces, violating the USB 2.0 specification. In such cases, the hub driver may bind to an unexpected interface (e.g., interface 1 instead of 0), causing usb_hub_to_struct_hub() to return an invalid pointer that is subsequently dereferenced in usb_hub_adjust_deviceremovable(). An attacker with physical access or the ability to emulate a USB device can trigger a general protection fault and system crash. The fix involves validating that hub devices have only one configuration and one interface during the probing process.
Affected products
- Linux Linux Kernel 6.13.x before 6.13.4, 6.12.x before 6.12.16, 6.6.x before 6.6.79, 6.1.x before 6.1.129
Timeline
- 2025-01-22: patched: Initial patch authored by Alan Stern
- 2025-02-27: advisory: CVE-2025-21776 published
References
- https://git.kernel.org/stable/c/2240fed37afbcdb5e8b627bc7ad986891100e05d
- https://git.kernel.org/stable/c/49f077106fa07919a6a6dda99bb490dd1d1a8218
- https://git.kernel.org/stable/c/5b9778e1fe715700993ce436c152dc3b7df0b490
- https://git.kernel.org/stable/c/62d8f4c5454dd39aded4f343720d1c5a1803cfef
- https://git.kernel.org/stable/c/c3720b04df84b5459050ae4e03ec7d545652f897
- https://git.kernel.org/stable/c/d343fe0fad5c1d689775f2dda24a85ce98e29566
- https://git.kernel.org/stable/c/d3a67adb365cdfdac4620daf38a82e57ca45806c