LiveActive security incident?Get immediate response
CVE Record

CVE-2022-49936: USB: core: Prevent nested device-reset calls

In the Linux kernel, the following vulnerability has been resolved: USB: core: Prevent nested device-reset calls Automatic kernel fuzzing revealed a recursive locking violation in usb-storage: ============================================ WARNING: possible recursive locking detected 5.18.0 #3 Not tainted -------------------------------------------- kworker/1:3/1205 is trying to acquire lock: ffff888018638db8 (&us_interface_key[i]){+.+.}-{3:3}, at: usb_stor_pre_reset+0x35/0x40 drivers/usb/storage/usb.c:230 but task is already holding lock: ffff888018638db8 (&us_interface_key[i]){+.+.}-{3:3}, at: usb_stor_pre_reset+0x35/0x40 drivers/usb/storage/usb.c:230 ... stack backtrace: CPU: 1 PID: 1205 Comm: kworker/1:3 Not tainted 5.18.0 #3 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014 Workqueue: usb_hub_wq hub_event Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106 print_deadlock_bug kernel/locking/lockdep.c:2988 [inline] check_deadlock kernel/locking/lockdep.c:3031 [inline] validate_chain kernel/locking/lockdep.c:3816 [inline] __lock_acquire.cold+0x152/0x3ca kernel/locking/lockdep.c:5053 lock_acquire kernel/locking/lockdep.c:5665 [inline] lock_acquire+0x1ab/0x520 kernel/locking/lockdep.c:5630 __mutex_lock_common kernel/locking/mutex.c:603 [inline] __mutex_lock+0x14f/0x1610 kernel/locking/mutex.c:747 usb_stor_pre_reset+0x35/0x40 drivers/usb/storage/usb.c:230 usb_reset_device+0x37d/0x9a0 drivers/usb/core/hub.c:6109 r871xu_dev_remove+0x21a/0x270 drivers/staging/rtl8712/usb_intf.c:622 usb_unbind_interface+0x1bd/0x890 drivers/usb/core/driver.c:458 device_remove drivers/base/dd.c:545 [inline] device_remove+0x11f/0x170 drivers/base/dd.c:537 __device_release_driver drivers/base/dd.c:1222 [inline] device_release_driver_internal+0x1a7/0x2f0 drivers/base/dd.c:1248 usb_driver_release_interface+0x102/0x180 drivers/usb/core/driver.c:627 usb_forced_unbind_intf+0x4d/0xa0 drivers/usb/core/driver.c:1118 usb_reset_device+0x39b/0x9a0 drivers/usb/core/hub.c:6114 This turned out not to be an error in usb-storage but rather a nested device reset attempt. That is, as the rtl8712 driver was being unbound from a composite device in preparation for an unrelated USB reset (that driver does not have pre_reset or post_reset callbacks), its ->remove routine called usb_reset_device() -- thus nesting one reset call within another. Performing a reset as part of disconnect processing is a questionable practice at best. However, the bug report points out that the USB core does not have any protection against nested resets. Adding a reset_in_progress flag and testing it will prevent such errors in the future.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue is a USB core bug where one device reset can be started inside another reset. That can trigger recursive locking problems during USB device removal or reset handling. The source does not provide a CVSS score, business impact rating, or evidence of exploitation.

Executive priority

Treat as a kernel maintenance item unless your environment relies heavily on USB device handling. There is no cited active exploitation or severity score, but kernel flaws can affect stability and should be addressed through normal patch governance.

Technical view

Automatic kernel fuzzing found recursive locking during USB reset handling. The root cause was a nested usb_reset_device() call while another reset was already preparing interface unbind processing. The fix adds a reset_in_progress guard in USB core to prevent nested resets.

Likely exposure

Exposure is limited to Linux systems running affected kernel versions with USB core reset paths reachable. The issue is most relevant where USB devices, composite devices, or related drivers are used. Exact distribution package exposure is not provided in the bundle.

Exploitation context

The only cited discovery context is automated kernel fuzzing. KEV status is false, and the bundle includes no cited evidence of active exploitation, public exploit use, or weaponized proof of concept.

Researcher notes

The record identifies a USB core state-management flaw, not a usb-storage-specific bug. The evidence points to recursive locking from nested reset handling involving rtl8712 removal during unrelated USB reset preparation. Impact boundaries and attacker prerequisites are not fully described.

Mitigation direction

  • Update to a Linux kernel build containing the referenced stable USB core fix.
  • Check distribution vendor advisories for the exact fixed package version.
  • Prioritize systems that accept removable, peripheral, or passthrough USB devices.
  • Avoid claiming remediation complete until the running kernel maps to a fixed build.

Validation and detection

  • Inventory running kernel versions across Linux assets.
  • Map kernels to vendor advisories or stable commits listed for this CVE.
  • Identify systems with exposed or operationally important USB device paths.
  • Review kernel logs for USB reset, unbind, or lock warning patterns.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-49936 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
9Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70, 78d9a487ee961c356e1a934d9a92eca38ffb3a70unaffected
LinuxLinux2.6.27, 0, 4.9.328, 4.14.293, 4.19.258, 5.4.213, 5.10.142, 5.15.66, 5.19.8, 6.0affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.