CVE-2025-37812

Source
https://cve.org/CVERecord?id=CVE-2025-37812
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37812.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37812
Downstream
Related
Published
2025-05-08T06:26:09.355Z
Modified
2026-03-20T12:42:28.992378Z
Summary
usb: cdns3: Fix deadlock when using NCM gadget
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: cdns3: Fix deadlock when using NCM gadget

The cdns3 driver has the same NCM deadlock as fixed in cdnsp by commit 58f2fcb3a845 ("usb: cdnsp: Fix deadlock issue during using NCM gadget").

Under PREEMPT_RT the deadlock can be readily triggered by heavy network traffic, for example using "iperf --bidir" over NCM ethernet link.

The deadlock occurs because the threaded interrupt handler gets preempted by a softirq, but both are protected by the same spinlock. Prevent deadlock by disabling softirq during threaded irq handler.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37812.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7733f6c32e36ff9d7adadf40001039bf219b1cbe
Fixed
eebfb64c624fc738b669100173344fb441c5e719
Fixed
59a760e4796a3cd88d8b9d7706e0a638de677751
Fixed
b96239582531775f2fdcb14de29bdb6870fd4c8c
Fixed
c27db84ed44e50ff90d9e3a2a25fae2e0a0fa015
Fixed
48a62deb857f0694f611949015e70ad194d97159
Fixed
74cd6e408a4c010e404832f0e4609d29bf1d0c41
Fixed
09e90a9689a4aac7a2f726dc2aa472b0b37937b7
Fixed
a1059896f2bfdcebcdc7153c3be2307ea319501f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37812.json"