« Volver al listado

CVE-2025-38404

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: displayport: Fix potential deadlock

The deadlock can occur due to a recursive lock acquisition of `cros_typec_altmode_data::mutex`. The call chain is as follows: 1. cros_typec_altmode_work() acquires the mutex 2. typec_altmode_vdm() -> dp_altmode_vdm() -> 3. typec_altmode_exit() -> cros_typec_altmode_exit() 4. cros_typec_altmode_exit() attempts to acquire the mutex again

To prevent this, defer the `typec_altmode_exit()` call by scheduling it rather than calling it directly from within the mutex-protected context.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-38404",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e0359c66c1beccbe90119a63391678eabda38007",
              "lessThan": "749d9076735fb497aae60fbea9fff563f9ea3254",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e3fb6c2c3939b4aad203cacdd613a62ce1fd032c",
              "lessThan": "eb08fca56f1f39e4038cb9bac9864464b13b00aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56846793f105cf2b39ecbde4f3ae86342091f6fc",
              "lessThan": "7be0d1ea71f52595499da39cea484a895e8ed042",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8e8a69b1f8c59f0505f8a1c0fb77191f27b75011",
              "lessThan": "76cf1f33e7319fe74c94ac92f9814094ee8cc84b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8851e40587013db00b71d4aeaae30f5fd59b0eec",
              "lessThan": "63cff9f57e86b2dc25d7487ca0118df89a665296",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "10cc2cfd3e5d0e0ec7590c4bee8bcea10e5492c4",
              "lessThan": "c782f98eef14197affa8a7b91e6981420f109ea9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8f6a4fa7b663468bb304cb885b93326e025ae005",
              "lessThan": "80c25d7916a44715338d4f8924c8e52af50d0b9f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b38ffb38c91afd4dc387608db26f6fc34ed40b",
              "lessThan": "099cf1fbb8afc3771f408109f62bdec66f85160e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/typec/altmodes/displayport.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.143",
              "lessThan": "6.1.144",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.96",
              "lessThan": "6.6.97",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.36",
              "lessThan": "6.12.37",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.5",
              "lessThan": "6.15.6",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/usb/typec/altmodes/displayport.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-25T14:15:31.950",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/099cf1fbb8afc3771f408109f62bdec66f85160e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/63cff9f57e86b2dc25d7487ca0118df89a665296",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/749d9076735fb497aae60fbea9fff563f9ea3254",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/76cf1f33e7319fe74c94ac92f9814094ee8cc84b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7be0d1ea71f52595499da39cea484a895e8ed042",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/80c25d7916a44715338d4f8924c8e52af50d0b9f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c782f98eef14197affa8a7b91e6981420f109ea9",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eb08fca56f1f39e4038cb9bac9864464b13b00aa",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-667"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: displayport: Fix potential deadlock\n\nThe deadlock can occur due to a recursive lock acquisition of\n`cros_typec_altmode_data::mutex`.\nThe call chain is as follows:\n1. cros_typec_altmode_work() acquires the mutex\n2. typec_altmode_vdm() -> dp_altmode_vdm() ->\n3. typec_altmode_exit() -> cros_typec_altmode_exit()\n4. cros_typec_altmode_exit() attempts to acquire the mutex again\n\nTo prevent this, defer the `typec_altmode_exit()` call by scheduling\nit rather than calling it directly from within the mutex-protected\ncontext."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: usb: typec: displayport: Soluciona un posible bloqueo El bloqueo puede ocurrir debido a una adquisición de bloqueo recursiva de `cros_typec_altmode_data::mutex`. La cadena de llamadas es la siguiente: 1. cros_typec_altmode_work() adquiere el mutex 2. typec_altmode_vdm() -> dp_altmode_vdm() -> 3. typec_altmode_exit() -> cros_typec_altmode_exit() 4. cros_typec_altmode_exit() intenta adquirir el mutex de nuevo Para evitar esto, aplaza la llamada a `typec_altmode_exit()` programándola en lugar de llamarla directamente desde dentro del contexto protegido por mutex."
    }
  ],
  "lastModified": "2026-06-17T09:16:47.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.1.143:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC911939-54F8-4A96-9EAD-B332B4105848"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.6.96:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4BFAA60-0B04-414F-8687-99789216F0F2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.12.36:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6822DD31-0F5F-45F9-BF68-F5D92B0C5A6F"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C9A4EA6-40DD-44AC-AEDD-0246F4590C75"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D4894DB-CCFE-4602-B1BF-3960B2E19A01"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09709862-E348-4378-8632-5A7813EDDC86"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "415BF58A-8197-43F5-B3D7-D1D63057A26E"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0517869-312D-4429-80C2-561086E1421C"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}