{"id":"DEBIAN-CVE-2025-68327","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: renesas_usbhs: Fix synchronous external abort on unbind  A synchronous external abort occurs on the Renesas RZ/G3S SoC if unbind is executed after the configuration sequence described above:  modprobe usb_f_ecm modprobe libcomposite modprobe configfs cd /sys/kernel/config/usb_gadget mkdir -p g1 cd g1 echo \"0x1d6b\" \u003e idVendor echo \"0x0104\" \u003e idProduct mkdir -p strings/0x409 echo \"0123456789\" \u003e strings/0x409/serialnumber echo \"Renesas.\" \u003e strings/0x409/manufacturer echo \"Ethernet Gadget\" \u003e strings/0x409/product mkdir -p functions/ecm.usb0 mkdir -p configs/c.1 mkdir -p configs/c.1/strings/0x409 echo \"ECM\" \u003e configs/c.1/strings/0x409/configuration  if [ ! -L configs/c.1/ecm.usb0 ]; then         ln -s functions/ecm.usb0 configs/c.1 fi  echo 11e20000.usb \u003e UDC echo 11e20000.usb \u003e /sys/bus/platform/drivers/renesas_usbhs/unbind  The displayed trace is as follows:   Internal error: synchronous external abort: 0000000096000010 [#1] SMP  CPU: 0 UID: 0 PID: 188 Comm: sh Tainted: G M 6.17.0-rc7-next-20250922-00010-g41050493b2bd #55 PREEMPT  Tainted: [M]=MACHINE_CHECK  Hardware name: Renesas SMARC EVK version 2 based on r9a08g045s33 (DT)  pstate: 604000c5 (nZCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : usbhs_sys_function_pullup+0x10/0x40 [renesas_usbhs]  lr : usbhsg_update_pullup+0x3c/0x68 [renesas_usbhs]  sp : ffff8000838b3920  x29: ffff8000838b3920 x28: ffff00000d585780 x27: 0000000000000000  x26: 0000000000000000 x25: 0000000000000000 x24: ffff00000c3e3810  x23: ffff00000d5e5c80 x22: ffff00000d5e5d40 x21: 0000000000000000  x20: 0000000000000000 x19: ffff00000d5e5c80 x18: 0000000000000020  x17: 2e30303230316531 x16: 312d7968703a7968 x15: 3d454d414e5f4344  x14: 000000000000002c x13: 0000000000000000 x12: 0000000000000000  x11: ffff00000f358f38 x10: ffff00000f358db0 x9 : ffff00000b41f418  x8 : 0101010101010101 x7 : 7f7f7f7f7f7f7f7f x6 : fefefeff6364626d  x5 : 8080808000000000 x4 : 000000004b5ccb9d x3 : 0000000000000000  x2 : 0000000000000000 x1 : ffff800083790000 x0 : ffff00000d5e5c80  Call trace:  usbhs_sys_function_pullup+0x10/0x40 [renesas_usbhs] (P)  usbhsg_pullup+0x4c/0x7c [renesas_usbhs]  usb_gadget_disconnect_locked+0x48/0xd4  gadget_unbind_driver+0x44/0x114  device_remove+0x4c/0x80  device_release_driver_internal+0x1c8/0x224  device_release_driver+0x18/0x24  bus_remove_device+0xcc/0x10c  device_del+0x14c/0x404  usb_del_gadget+0x88/0xc0  usb_del_gadget_udc+0x18/0x30  usbhs_mod_gadget_remove+0x24/0x44 [renesas_usbhs]  usbhs_mod_remove+0x20/0x30 [renesas_usbhs]  usbhs_remove+0x98/0xdc [renesas_usbhs]  platform_remove+0x20/0x30  device_remove+0x4c/0x80  device_release_driver_internal+0x1c8/0x224  device_driver_detach+0x18/0x24  unbind_store+0xb4/0xb8  drv_attr_store+0x24/0x38  sysfs_kf_write+0x7c/0x94  kernfs_fop_write_iter+0x128/0x1b8  vfs_write+0x2ac/0x350  ksys_write+0x68/0xfc  __arm64_sys_write+0x1c/0x28  invoke_syscall+0x48/0x110  el0_svc_common.constprop.0+0xc0/0xe0  do_el0_svc+0x1c/0x28  el0_svc+0x34/0xf0  el0t_64_sync_handler+0xa0/0xe4  el0t_64_sync+0x198/0x19c  Code: 7100003f 1a9f07e1 531c6c22 f9400001 (79400021)  ---[ end trace 0000000000000000 ]---  note: sh[188] exited with irqs disabled  note: sh[188] exited with preempt_count 1  The issue occurs because usbhs_sys_function_pullup(), which accesses the IP registers, is executed after the USBHS clocks have been disabled. The problem is reproducible on the Renesas RZ/G3S SoC starting with the addition of module stop in the clock enable/disable APIs. With module stop functionality enabled, a bus error is expected if a master accesses a module whose clock has been stopped and module stop activated.  Disable the IP clocks at the end of remove.","modified":"2026-09-01T16:06:21.714094950Z","published":"2025-12-22T17:16:00.353Z","upstream":["CVE-2025-68327"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-68327"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.159-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.147-1","6.1.148-1","6.1.153-1","6.1.158-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68327.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.63-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68327.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.17.11-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68327.json"}}],"schema_version":"1.9.0"}