CVE-2025-38376
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38376 was discovered in the Linux kernel and disclosed on July 25, 2025. The vulnerability affects the USB chipidea UDC (USB Device Controller) component during system suspend/resume operations. This issue specifically impacts systems where USB gadget is enabled as Ethernet and data transfer occurs over USB Ethernet connections (NVD).

Technical details

The vulnerability occurs when the USB device controller is suspended while the USB bus remains active. In this scenario, the USB host continues to transfer data with the device, and the device continues to queue USB requests after the controller is suspended and its clock is gated off. When the UDC driver attempts to access registers at this point, the system hangs (NVD).

Impact

When exploited, this vulnerability can cause system hangs during suspend operations, particularly when there is active data transfer over USB Ethernet connections. The issue is triggered specifically when a delayed TCP ACK packet occurs after the controller is suspended (NVD).

Mitigation and workarounds

The correct mitigation involves disconnecting the device from the host when the USB bus is not in suspend state. This allows the host to receive the disconnect event and stop data transfer in time. The system is designed to automatically reconnect the device after system resume. For USB wakeup functionality, the connection is maintained only when the USB device controller has enabled wakeup capability (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management