PT-2025-37482 · Dwc3+7 · Dwc3+7

Published

2025-01-01

·

Updated

2026-04-20

·

CVE-2025-39801

CVSS v2.0

5.7

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description This issue addresses a rarely observed endpoint command timeout in the dwc3 USB controller, which can cause a kernel panic when 'panic on warn' is enabled or unnecessary call trace prints when 'panic on warn' is disabled. This was observed during fast software-controlled connect/disconnect testcases, specifically on Exynos platforms where control transfers from a previous connect were not completed before a disconnect sequence was initiated, leading to timeouts when processing USB ENDPOINT HALT feature requests. The vulnerability occurs during the processing of device endpoint commands. The affected functions include dwc3 thread interrupt, dwc3 ep0 interrupt, configfs composite setup, composite setup, usb ep queue, dwc3 gadget ep0 queue, dwc3 gadget ep0 queue, dwc3 ep0 do control data, dwc3 send gadget ep cmd, and dwc3 ep0 reset state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Weakness Enumeration

Related Identifiers

AZL-67344
AZL-75116
BDU:2025-15687
CVE-2025-39801
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-2F6D-8AF4-1251
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Exynos
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu
Dwc3