PT-2025-27691 · Linux+4 · Linux Kernel+4

Published

2025-05-19

·

Updated

2026-05-07

·

CVE-2025-38105

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A vulnerability in the Linux kernel's USB-audio MIDI code has been identified. The issue arises when the driver is freed without the disconnect call, leaving a timer in an active state. This results in a kernel warning when the debug configuration is enabled. The problem occurs due to the improper initialization of the timer.
Recommendations: For the Linux kernel, to resolve the issue, put timer shutdown sync() at snd usbmidi free(), so that the timer can be killed properly. Additionally, replace the existing timer delete sync() at the disconnect callback with timer shutdown sync().

Exploit

Fix

Improper Initialization

Weakness Enumeration

Related Identifiers

AZL-64505
AZL-70627
BDU:2025-08996
CVE-2025-38105
ECHO-43F9-93DB-047F
SUSE-SU-2025:02846-1
SUSE-SU-2025:02853-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:02996-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:03023-1
SUSE-SU-2025:20577-1
SUSE-SU-2025:20586-1
SUSE-SU-2025:20601-1
SUSE-SU-2025:20602-1
SUSE-SU-2025_02846-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2025_03023-1
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu