Junglewise Threat Intelligence

CVE-2026-80659: Linux kernel mmc vub300 recursive mutex deadlock

CVE-2026-80659 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's vub300 MMC/SD card reader driver contains a deadlock vulnerability in its USB device reset logic. When a command timeout occurs, the driver attempts to reset the USB device while still holding a mutex lock that the reset process also tries to acquire, causing the device to become unresponsive and halting card I/O operations.

Technical details

The vulnerability is a recursive mutex deadlock (CWE-667) in the vub300 mmc driver's command handling path. The vub300_cmndwork_thread() function holds cmd_mutex while sending commands and waiting for responses. When the response wait times out, __vub300_command_response() calls usb_reset_device() to reset the USB device, which synchronously re-enters the driver through vub300_pre_reset(). The pre_reset handler attempts to acquire the same cmd_mutex, causing a same-task recursive lock acquisition and system deadlock. The fix defers the device reset until after the command worker releases cmd_mutex, eliminating the lock contention while preserving request completion ordering.

Affected products

  • Linux Linux kernel unknown

Timeline

  • 2026-08-28: disclosed

Related threats