{"id":"DEBIAN-CVE-2024-56687","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: musb: Fix hardware lockup on first Rx endpoint request  There is a possibility that a request's callback could be invoked from usb_ep_queue() (call trace below, supplemented with missing calls):  req-\u003ecomplete from usb_gadget_giveback_request \t(drivers/usb/gadget/udc/core.c:999) usb_gadget_giveback_request from musb_g_giveback \t(drivers/usb/musb/musb_gadget.c:147) musb_g_giveback from rxstate \t(drivers/usb/musb/musb_gadget.c:784) rxstate from musb_ep_restart \t(drivers/usb/musb/musb_gadget.c:1169) musb_ep_restart from musb_ep_restart_resume_work \t(drivers/usb/musb/musb_gadget.c:1176) musb_ep_restart_resume_work from musb_queue_resume_work \t(drivers/usb/musb/musb_core.c:2279) musb_queue_resume_work from musb_gadget_queue \t(drivers/usb/musb/musb_gadget.c:1241) musb_gadget_queue from usb_ep_queue \t(drivers/usb/gadget/udc/core.c:300)  According to the docstring of usb_ep_queue(), this should not happen:  \"Note that @req's -\u003ecomplete() callback must never be called from within usb_ep_queue() as that can create deadlock situations.\"  In fact, a hardware lockup might occur in the following sequence:  1. The gadget is initialized using musb_gadget_enable(). 2. Meanwhile, a packet arrives, and the RXPKTRDY flag is set, raising an    interrupt. 3. If IRQs are enabled, the interrupt is handled, but musb_g_rx() finds an    empty queue (next_request() returns NULL). The interrupt flag has    already been cleared by the glue layer handler, but the RXPKTRDY flag    remains set. 4. The first request is enqueued using usb_ep_queue(), leading to the call    of req-\u003ecomplete(), as shown in the call trace above. 5. If the callback enables IRQs and another packet is waiting, step (3)    repeats. The request queue is empty because usb_g_giveback() removes the    request before invoking the callback. 6. The endpoint remains locked up, as the interrupt triggered by hardware    setting the RXPKTRDY flag has been handled, but the flag itself remains    set.  For this scenario to occur, it is only necessary for IRQs to be enabled at some point during the complete callback. This happens with the USB Ethernet gadget, whose rx_complete() callback calls netif_rx(). If called in the task context, netif_rx() disables the bottom halves (BHs). When the BHs are re-enabled, IRQs are also enabled to allow soft IRQs to be processed. The gadget itself is initialized at module load (or at boot if built-in), but the first request is enqueued when the network interface is brought up, triggering rx_complete() in the task context via ioctl(). If a packet arrives while the interface is down, it can prevent the interface from receiving any further packets from the USB host.  The situation is quite complicated with many parties involved. This particular issue can be resolved in several possible ways:  1. Ensure that callbacks never enable IRQs. This would be difficult to    enforce, as discovering how netif_rx() interacts with interrupts was    already quite challenging and u_ether is not the only function driver.    Similar \"bugs\" could be hidden in other drivers as well. 2. Disable MUSB interrupts in musb_g_giveback() before calling the callback    and re-enable them afterwars (by calling musb_{dis,en}able_interrupts(),    for example). This would ensure that MUSB interrupts are not handled    during the callback, even if IRQs are enabled. In fact, it would allow    IRQs to be enabled when releasing the lock. However, this feels like an    inelegant hack. 3. Modify the interrupt handler to clear the RXPKTRDY flag if the request    queue is empty. While this approach also feels like a hack, it wastes    CPU time by attempting to handle incoming packets when the software is    not ready to process them. 4. Flush the Rx FIFO instead of calling rxstate() in musb_ep_restart().    This ensures that the hardware can receive packets when there is at    least one request in the queue. Once I ---truncated---","modified":"2026-09-15T09:03:17.319378673Z","published":"2024-12-28T10:15:12.153Z","upstream":["CVE-2024-56687"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56687"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.123-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56687.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56687.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56687.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}