{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-53580",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-10-04T15:14:15.926Z",
        "datePublished": "2025-10-04T15:43:57.064Z",
        "dateUpdated": "2026-08-05T09:14:56.489Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:14:56.489Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: Gadget: core: Help prevent panic during UVC unconfigure\n\nAvichal Rakesh reported a kernel panic that occurred when the UVC\ngadget driver was removed from a gadget's configuration.  The panic\ninvolves a somewhat complicated interaction between the kernel driver\nand a userspace component (as described in the Link tag below), but\nthe analysis did make one thing clear: The Gadget core should\naccomodate gadget drivers calling usb_gadget_deactivate() as part of\ntheir unbind procedure.\n\nCurrently this doesn't work.  gadget_unbind_driver() calls\ndriver->unbind() while holding the udc->connect_lock mutex, and\nusb_gadget_deactivate() attempts to acquire that mutex, which will\nresult in a deadlock.\n\nThe simple fix is for gadget_unbind_driver() to release the mutex when\ninvoking the ->unbind() callback.  There is no particular reason for\nit to be holding the mutex at that time, and the mutex isn't held\nwhile the ->bind() callback is invoked.  So we'll drop the mutex\nbefore performing the unbind callback and reacquire it afterward.\n\nWe'll also add a couple of comments to usb_gadget_activate() and\nusb_gadget_deactivate().  Because they run in process context they\nmust not be called from a gadget driver's ->disconnect() callback,\nwhich (according to the kerneldoc for struct usb_gadget_driver in\ninclude/linux/usb/gadget.h) may run in interrupt context.  This may\nhelp prevent similar bugs from arising in the future."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Both halves of the bug are reached through local interfaces — V4L2 file operations on the UVC gadget's `/dev/videoX` node and gadget (re)configuration via configfs/driver model — not through USB bus traffic from a host or over a network.\nAC:L - The attacker controls one side of the race entirely (when to open/subscribe/close the V4L2 handle) and gets an explicit signal plus a ~1.5 s window (device-removal uevent followed by `uvc_function_unbind()`'s 500 ms + 1000 ms timeouts), so the deadlock and subsequent use-after-free can be hit reliably and repeatedly.\nPR:L - An unprivileged local user with access to the UVC gadget video node (commonly group `video` on embedded, kiosk, and Android-derived devices) can hold the handle open and subscribed, which is all that is needed to turn gadget teardown into a deadlock and use-after-free; no root or capability is required on the attacking side.\nUI:N - Gadget unbind is driven by routine system events on affected devices (USB mode/role switches, cable-driven reconfiguration by system daemons, dwc3 DRD role change), not by a deliberate action of a separate victim user.\nS:U - The deadlock and the resulting use-after-free are confined to the kernel of the affected system; no VM, IOMMU, or other security-authority boundary is crossed.\nC:H - After the deadlock breaks, the release path operates on a destroyed workqueue and freed endpoint/request/descriptor objects; a local attacker who reclaims those allocations during the long, attacker-observable window obtains a kernel-memory read primitive.\nI:H - The same use-after-free — `cancel_work_sync()`/`queue_work()` on a freed `async_wq` and `usb_ep_dequeue()` on torn-down endpoints — dereferences attacker-groomable heap contents including function pointers, giving a write/control-flow-hijack primitive.\nA:H - The reported outcome is a kernel panic during UVC unconfigure, and the direct-call variant self-deadlocks on `udc->connect_lock` in uninterruptible state, permanently wedging the task and the entire USB gadget subsystem."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/usb/gadget/udc/core.c"
                    ],
                    "versions": [
                        {
                            "version": "d8195536ce2624e2947d9f56b1a61e7a27874bd3",
                            "lessThan": "bed19d95fcb9c98dfaa9585922b39a2dfba7898d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "286d9975a838d0a54da049765fa1d1fb96b89682",
                            "lessThan": "8c1edc00db65f6d4408b3d1cd845e8da3b9e0ca4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "286d9975a838d0a54da049765fa1d1fb96b89682",
                            "lessThan": "65dadb2beeb7360232b09ebc4585b54475dfee06",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "85102a45c7390caf124a3a5796574446f1e037b9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6.1.35",
                            "lessThan": "6.1.46",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.3.9",
                            "lessThan": "6.4",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/usb/gadget/udc/core.c"
                    ],
                    "versions": [
                        {
                            "version": "6.4",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.4",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.46",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.4.11",
                            "lessThanOrEqual": "6.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.5",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.35",
                                    "versionEndExcluding": "6.1.46"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.4",
                                    "versionEndExcluding": "6.4.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.4",
                                    "versionEndExcluding": "6.5"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3.9"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/bed19d95fcb9c98dfaa9585922b39a2dfba7898d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/8c1edc00db65f6d4408b3d1cd845e8da3b9e0ca4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/65dadb2beeb7360232b09ebc4585b54475dfee06"
                }
            ],
            "title": "USB: Gadget: core: Help prevent panic during UVC unconfigure",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}