Executive brief
A vulnerability in the Linux kernel's USB driver could cause a system crash or instability when a USB device is disconnected during a power-saving suspend state. This occurs because the system incorrectly attempts to perform "sleepable" operations while in a restricted processing mode that forbids them. While primarily a stability issue, it could impact the availability of systems using specific USB controllers.
Technical details
A concurrency issue exists in the dwc3 USB driver (drivers/usb/dwc3/gadget.c) where dwc3_gadget_suspend() executes the gadget disconnect callback while holding a spinlock with interrupts disabled. If the gadget driver's disconnect function contains sleepable operations, it triggers a 'sleeping function called from invalid context' error (Lockdep BUG). This is caused by dwc3_gadget_suspend() taking dwc->lock via spin_lock_irqsave() before calling dwc3_disconnect_gadget(). The fix introduces a sleepable wrapper that snapshots the callback and executes it after releasing the lock and restoring interrupts.
Affected products
- Linux Linux Kernel 5.15.128 to 5.15.212, 6.1.x, 6.6.x, 6.10.x
Timeline
- 2026-06-12: disclosed: Initial patch submitted by Runyu Xiao
- 2026-07-08: patched: Patch committed to stable tree
- 2026-07-25: advisory: CVE published
References
- https://git.kernel.org/stable/c/010382937fb69892b3469ac4d30af072262f59e8
- https://git.kernel.org/stable/c/48958478cb8dbc429a5b19f36e866b63d6297d1d
- https://git.kernel.org/stable/c/5e5798880eb1533a7de6fb68eb14b2d8202ebf76
- https://git.kernel.org/stable/c/642e04f5c292d04070ae6e4374fbf14cc40a2465
- https://git.kernel.org/stable/c/b399be2958456efe1b64b19c55a54a24e9035769
- https://git.kernel.org/stable/c/c4e232bd07fe2b69a6e5c380db41dd36b95e0524
- https://git.kernel.org/stable/c/e0e4f15d4225fb7156cc0e3c21eb8953114f9b89