CVE-2022-49943: USB: gadget: Fix obscure lockdep violation for udc_mutex
In the Linux kernel, the following vulnerability has been resolved:
USB: gadget: Fix obscure lockdep violation for udc_mutex
A recent commit expanding the scope of the udc_lock mutex in the
gadget core managed to cause an obscure and slightly bizarre lockdep
violation. In abbreviated form:
======================================================
WARNING: possible circular locking dependency detected
5.19.0-rc7+ #12510 Not tainted
------------------------------------------------------
udevadm/312 is trying to acquire lock:
ffff80000aae1058 (udc_lock){+.+.}-{3:3}, at: usb_udc_uevent+0x54/0xe0
but task is already holding lock:
ffff000002277548 (kn->active#4){++++}-{0:0}, at: kernfs_seq_start+0x34/0xe0
which lock already depends on the new lock.
the existing dependency chain (in reverse order) is:
-> #3 (kn->active#4){++++}-{0:0}:
lock_acquire+0x68/0x84
__kernfs_remove+0x268/0x380
kernfs_remove_by_name_ns+0x58/0xac
sysfs_remove_file_ns+0x18/0x24
device_del+0x15c/0x440
-> #2 (device_links_lock){+.+.}-{3:3}:
lock_acquire+0x68/0x84
__mutex_lock+0x9c/0x430
mutex_lock_nested+0x38/0x64
device_link_remove+0x3c/0xa0
_regulator_put.part.0+0x168/0x190
regulator_put+0x3c/0x54
devm_regulator_release+0x14/0x20
-> #1 (regulator_list_mutex){+.+.}-{3:3}:
lock_acquire+0x68/0x84
__mutex_lock+0x9c/0x430
mutex_lock_nested+0x38/0x64
regulator_lock_dependent+0x54/0x284
regulator_enable+0x34/0x80
phy_power_on+0x24/0x130
__dwc2_lowlevel_hw_enable+0x100/0x130
dwc2_lowlevel_hw_enable+0x18/0x40
dwc2_hsotg_udc_start+0x6c/0x2f0
gadget_bind_driver+0x124/0x1f4
-> #0 (udc_lock){+.+.}-{3:3}:
__lock_acquire+0x1298/0x20cc
lock_acquire.part.0+0xe0/0x230
lock_acquire+0x68/0x84
__mutex_lock+0x9c/0x430
mutex_lock_nested+0x38/0x64
usb_udc_uevent+0x54/0xe0
Evidently this was caused by the scope of udc_mutex being too large.
The mutex is only meant to protect udc->driver along with a few other
things. As far as I can tell, there's no reason for the mutex to be
held while the gadget core calls a gadget driver's ->bind or ->unbind
routine, or while a UDC is being started or stopped. (This accounts
for link #1 in the chain above, where the mutex is held while the
dwc2_hsotg_udc is started as part of driver probing.)
Gadget drivers' ->disconnect callbacks are problematic. Even though
usb_gadget_disconnect() will now acquire the udc_mutex, there's a
window in usb_gadget_bind_driver() between the times when the mutex is
released and the ->bind callback is invoked. If a disconnect occurred
during that window, we could call the driver's ->disconnect routine
before its ->bind routine. To prevent this from happening, it will be
necessary to prevent a UDC from connecting while it has no gadget
driver. This should be done already but it doesn't seem to be;
currently usb_gadget_connect() has no check for this. Such a check
will have to be added later.
Some degree of mutual exclusion is required in soft_connect_store(),
which can dereference udc->driver at arbitrary times since it is a
sysfs callback. The solution here is to acquire the gadget's device
lock rather than the udc_mutex. Since the driver core guarantees that
the device lock is always held during driver binding and unbinding,
this will make the accesses in soft_connect_store() mutually exclusive
with any changes to udc->driver.
Lastly, it turns out there is one place which should hold the
udc_mutex but currently does not: The function_show() routine needs
protection while it dereferences udc->driver. The missing lock and
unlock calls are added.
Security readout for executives and security teams
Plain-English summary
CVE-2022-49943 is a Linux kernel USB gadget locking flaw. The source describes a possible circular locking dependency around udc_mutex during gadget driver binding, unbinding, UDC start/stop, and sysfs callbacks. Business urgency depends on whether your systems use USB gadget functionality; the bundle provides no CVSS, CWE, or exploitation evidence.
Executive priority
Treat as a targeted kernel maintenance item, not an emergency based on current evidence. Prioritize embedded, appliance, lab, or device-like Linux systems that rely on USB gadget behavior. Escalate if your vendor rates it higher or ties it to availability impact in your environment.
Technical view
The issue is in Linux kernel USB gadget core synchronization. udc_mutex was held across operations that could interact with regulator, device link, kernfs, and uevent locking, creating a lockdep circular dependency. The fix narrows udc_mutex scope, uses the gadget device lock for soft_connect_store, and adds missing protection in function_show.
Likely exposure
Likely exposure is limited to Linux systems running affected kernel code with USB gadget/UDC functionality. The bundle does not provide a distribution matrix, full vulnerable version range, or CPEs. General Linux servers without USB gadget use may have lower practical exposure, but this must be confirmed from kernel configuration and vendor packages.
Exploitation context
The provided sources do not show active exploitation, and KEV is false. The record describes a kernel concurrency and locking correctness issue, not an established public attack chain. No CVSS vector, CWE, exploit status, or attacker prerequisites are included in the source bundle.
Researcher notes
Evidence is limited to the CVE description and Linux stable commit references. The record lacks CVSS, CWE, CPEs, exploitability analysis, and distro-specific status. Analysis should focus on whether deployed kernels include the USB gadget core changes and whether local configurations exercise UDC binding, sysfs soft connect, or function_show paths.
Mitigation direction
Check vendor kernel advisories for packages containing the referenced stable commits.
Prioritize updates on Linux systems using USB gadget or UDC functionality.
Apply supported kernel updates rather than backporting manually where possible.
If updates are delayed, reduce unnecessary USB gadget exposure where operationally feasible.
Validation and detection
Inventory systems with Linux USB gadget or UDC functionality enabled.
Compare kernel source or package changelogs against the two referenced stable commits.
Confirm whether vendor kernels mark CVE-2022-49943 as fixed or not affected.
Include affected workflows in staging tests before production kernel rollout.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49943 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
3Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Jun 18, 2025, 10:59 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.