Review reviewHigh

CVE-2025-40140

Linux

In the Linux kernel, the following vulnerability has been resolved: net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast syzbot reported WARNING in rtl8150_start_xmit/usb_submit_urb. This is the sequence of events that leads to the warning: rtl8150_start_xmit() { netif_stop_queue(); usb_submit_urb(dev->tx_urb); } rtl8150_set_multicast() { netif_stop_queue(); netif_wake_queue(); <-- wakes up TX queue before URB is done } rtl8150_start_xmit() { netif_stop_queue(); usb_submit_urb(dev->tx_urb); <-- double submission } rtl8150_set_multicast being the ndo_set_rx_mode callback sho...

CVSS
8.8
EPSS
0.29%
21.5% percentile
CISA KEV
Not listed
Published
2025.11.12
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast syzbot reported WARNING in rtl8150_start_xmit/usb_submit_urb. This is the sequence of events that leads to the warning: rtl8150_start_xmit() { netif_stop_queue(); usb_submit_urb(dev->tx_urb); } rtl8150_set_multicast() { netif_stop_queue(); netif_wake_queue(); <-- wakes up TX queue before URB is done } rtl8150_start_xmit() { netif_stop_queue(); usb_submit_urb(dev->tx_urb); <-- double submission } rtl8150_set_multicast being the ndo_set_rx_mode callback sho...

Affected product and versions

Product
Linux
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cce3c0e21cdd15bcba5c35d3af1700186de8f187, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1a08a37ac03d07a1608a1592791041cac979fbc3, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 54f8ef1a970a8376e5846ed90854decf7c00555d, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 114e05344763a102a8844efd96ec06ba99293ccd, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6394bade9daab8e318c165fe43bba012bf13cd8e, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6053e47bbf212b93c051beb4261d7d5a409d0ce3, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9d72df7f5eac946f853bf49c428c4e87a17d91da, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 958baf5eaee394e5fd976979b0791a875f14a179, >= 2.6.12
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available