Executive brief
A vulnerability was identified in the Linux kernel's RTL8150 USB Ethernet driver. This flaw could allow an attacker on the same local network to cause a system crash or potentially execute unauthorized actions by triggering a race condition during network configuration. The issue stems from improper synchronization when handling multicast network traffic, which can lead to the system attempting to process the same data transmission twice simultaneously.
Technical details
A race condition exists in the rtl8150 USB Ethernet driver within the Linux kernel. The function `rtl8150_set_multicast` (the `ndo_set_rx_mode` callback) incorrectly calls `netif_stop_queue` and `netif_wake_queue`. Because these functions manage TX queue synchronization, calling `netif_wake_queue` prematurely allows `rtl8150_start_xmit` to be invoked before a previous USB Request Block (URB) submission is complete. This results in a double submission of `dev->tx_urb`, triggering a kernel warning and potential memory corruption. The fix involves removing the disruptive queue management calls from the multicast configuration path, as the network core already handles necessary synchronization.
Affected products
- Linux Linux Kernel 2.6.12 to 5.4.301, 5.10.246, 5.15.195, 6.1.156, 6.6.57, 6.10.14, 6.11.3
Timeline
- 2025-09-24: disclosed: Initial patch submitted by I Viswanath
- 2025-10-15: patched: Patch committed to stable branches
- 2025-11-12: advisory: CVE-2025-40140 published
References
- https://git.kernel.org/stable/c/114e05344763a102a8844efd96ec06ba99293ccd
- https://git.kernel.org/stable/c/1a08a37ac03d07a1608a1592791041cac979fbc3
- https://git.kernel.org/stable/c/54f8ef1a970a8376e5846ed90854decf7c00555d
- https://git.kernel.org/stable/c/6053e47bbf212b93c051beb4261d7d5a409d0ce3
- https://git.kernel.org/stable/c/6394bade9daab8e318c165fe43bba012bf13cd8e
- https://git.kernel.org/stable/c/958baf5eaee394e5fd976979b0791a875f14a179
- https://git.kernel.org/stable/c/9d72df7f5eac946f853bf49c428c4e87a17d91da