{"id":"DEBIAN-CVE-2023-54159","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: mtu3: fix kernel panic at qmu transfer done irq handler  When handle qmu transfer irq, it will unlock @mtu-\u003elock before give back request, if another thread handle disconnect event at the same time, and try to disable ep, it may lock @mtu-\u003elock and free qmu ring, then qmu irq hanlder may get a NULL gpd, avoid the KE by checking gpd's value before handling it.  e.g. qmu done irq on cpu0                 thread running on cpu1  qmu_done_tx()   handle gpd [0]     mtu3_requ_complete()        mtu3_gadget_ep_disable()       unlock @mtu-\u003elock         give back request         lock @mtu-\u003elock                                     mtu3_ep_disable()                                       mtu3_gpd_ring_free()                                    unlock @mtu-\u003elock       lock @mtu-\u003elock     get next gpd [1]  [1]: goto [0] to handle next gpd, and next gpd may be NULL.","modified":"2026-09-15T08:47:27.459096105Z","published":"2025-12-24T13:16:17.960Z","upstream":["CVE-2023-54159"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54159"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.37-1"}]}],"versions":["6.1.27-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54159.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54159.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54159.json"}}],"schema_version":"1.9.0"}