Junglewise Threat Intelligence

CVE-2025-39801: Linux kernel reachable assertion in dwc3 USB driver

CVE-2025-39801 · Severity: medium · CVSS 5.5 · Published 2025-09-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB driver could allow a local user to cause a system crash. This occurs during rapid connecting and disconnecting of USB devices on certain hardware platforms. If the system is configured to halt on warnings, these common hardware events can trigger a full system failure, impacting operational availability.

Technical details

A vulnerability classified as a Reachable Assertion (CWE-617) exists in the Linux kernel's dwc3 USB driver. The issue stems from the use of WARN_ON macros when device endpoint commands timeout, which is a condition that can occur naturally during fast software-controlled connect/disconnect sequences on Exynos and other platforms. If the kernel is booted with 'panic_on_warn' enabled, these timeouts trigger a kernel panic; otherwise, they generate unnecessary call traces. The fix involves replacing the WARN_ON assertions with rate-limited error logging to handle these expected hardware timing scenarios gracefully. The vulnerability is reachable by a local user capable of triggering USB gadget state changes.

Affected products

  • Linux Linux kernel up to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-09-15: disclosed
  • 2025-09-15: advisory
  • 2025-08-17: patched: Initial patch committed to stable tree

References

Related threats