usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
Published Dec 22, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
When a UAS device is unplugged during data transfer, there is a probability of a system panic occurring. The root cause is an access to an invalid memory address during URB callback handling. Specifically, this happens when the dma_direct_unmap_sg() function is called within the usb_hcd_unmap_urb_for_dma() interface, but the sg->dma_address field is 0 and the sg data structure has already been freed.
The SCSI driver sends transfer commands by invoking uas_queuecommand_lck() in uas.c, using the uas_submit_urbs() function to submit requests to USB. Within the uas_submit_urbs() implementation, three URBs (sense_urb, data_urb, and cmd_urb) are sequentially submitted. Device removal may occur at any point during uas_submit_urbs execution, which may result in URB submission failure. However, some URBs might have been successfully submitted before the failure, and uas_submit_urbs will return the -ENODEV error code in this case. The current error handling directly calls scsi_done(). In the SCSI driver, this eventually triggers scsi_complete() to invoke scsi_end_request() for releasing the sgtable. The successfully submitted URBs, when being unlinked to giveback, call usb_hcd_unmap_urb_for_dma() in hcd.c, leading to exceptions during sg unmapping operations since the sg data structure has already been freed.
This patch modifies the error condition check in the uas_submit_urbs() function. When a UAS device is removed but one or more URBs have already been successfully submitted to USB, it avoids immediately invoking scsi_done() and save the cmnd to devinfo->cmnd array. If the successfully submitted URBs is completed before devinfo->resetting being set, then the scsi_done() function will be called within uas_try_complete() after all pending URB operations are finalized. Otherwise, the scsi_done() function will be called within uas_zap_pending(), which is executed after usb_kill_anchored_urbs().
The error handling only takes effect when uas_queuecommand_lck() calls uas_submit_urbs() and returns the error value -ENODEV . In this case, the device is disconnected, and the flow proceeds to uas_disconnect(), where uas_zap_pending() is invoked to call uas_try_complete().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.10
- Version 5.10.247StatusunaffectedConstraints<=5.10.*
- Version 5.15.197StatusunaffectedConstraints<=5.15.*
- Version 6.1.159StatusunaffectedConstraints<=6.1.*
- Version 6.12.61StatusunaffectedConstraints<=6.12.*
- Version 6.17.11StatusunaffectedConstraints<=6.17.*
- Version 6.18StatusunaffectedConstraints<=*
- Version 6.6.119StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Physical removal of USB storage during I/O is the trigger. While this can happen accidentally, it can also be induced deliberately with physical access to the system.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.21% (0.00212) | 10.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.19% (0.00193) | 9.09th | v5 (v2026.06.15) |
| Dec 23, 2025 | 0.02% (0.00024) | 5.64th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2025-68331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2424341 Issue Tracking
- https://git.kernel.org/stable/c/26d56a9fcb2014b99e654127960aa0a48a391e3c
- https://git.kernel.org/stable/c/2b90a8131c83f6f2be69397d2b7d14d217d95d2f
- https://git.kernel.org/stable/c/426edbfc88b22601ea34a441a469092e7b301c52
- https://git.kernel.org/stable/c/6289fc489e94c9beb6be2b502ccc263663733d72
- https://git.kernel.org/stable/c/66ac05e7b0d6bbd1bee9fcf729e20fd4cce86d17
- https://git.kernel.org/stable/c/75f8e2643085db4f7e136fc6b368eb114dd80a64
- https://git.kernel.org/stable/c/e3a55221f4de080cb7a91ba10f01c4f708603f8d
- https://lore.kernel.org/linux-cve-announce/2025122219-CVE-2025-68331-e22f@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-68331
- https://www.cve.org/CVERecord?id=CVE-2025-68331
Change history (0)
No recorded changes yet.