SB2026081727 - Race condition in Linux kernel usb atm driver
Published: August 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-68456)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in the ueagle-atm USB driver disconnect handler when handling device removal during asynchronous pre-firmware loading. A local attacker can unplug a device while firmware loading is still in progress to cause a denial of service.
The issue is associated with the firmware sysfs fallback mechanism and manifests when device teardown runs concurrently with the asynchronous firmware request.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/509b51327320bdeaef1969248177a446ded073ab
- https://git.kernel.org/stable/c/76861031b43a18065d13f9ffb8595d25c7576005
- https://git.kernel.org/stable/c/bbfedc84714064ea4845e6b76f96316eb5bb65d8
- https://git.kernel.org/stable/c/c581e30ae5b332d8acef64475a211b3f82099941
- https://git.kernel.org/stable/c/d85f19aaef42a03e3e4765d659c761c8750a7f23
- https://git.kernel.org/stable/c/ddcdac47e1f2651c7be60e299f98faf981522797
- https://git.kernel.org/stable/c/e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf
- https://git.kernel.org/stable/c/f2a6abc670104fc3e383ee3b1cf35c070485e3df