Junglewise Threat Intelligence

CVE-2025-21776: Linux Kernel NULL pointer dereference in USB hub driver

CVE-2025-21776 · Severity: medium · CVSS 5.5 · Published 2025-02-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB hub driver could allow a specially crafted, non-compliant USB device to crash the system. By presenting more than one configuration or interface—which violates the USB 2.0 specification—the device triggers a memory error (NULL pointer dereference) during the initialization process. This results in a system crash (kernel oops), impacting the availability of the affected machine.

Technical details

A NULL pointer dereference exists in the Linux kernel's USB hub driver within the hub_probe function. The vulnerability is triggered when a USB device provides multiple configurations or interfaces, violating the USB 2.0 specification. In such cases, the hub driver may bind to an unexpected interface (e.g., interface 1 instead of 0), causing usb_hub_to_struct_hub() to return an invalid pointer that is subsequently dereferenced in usb_hub_adjust_deviceremovable(). An attacker with physical access or the ability to emulate a USB device can trigger a general protection fault and system crash. The fix involves validating that hub devices have only one configuration and one interface during the probing process.

Affected products

  • Linux Linux Kernel 6.13.x before 6.13.4, 6.12.x before 6.12.16, 6.6.x before 6.6.79, 6.1.x before 6.1.129

Timeline

  • 2025-01-22: patched: Initial patch authored by Alan Stern
  • 2025-02-27: advisory: CVE-2025-21776 published

References

Related threats