LiveActive security incident?Get immediate response
CVE Record

CVE-2022-49943: USB: gadget: Fix obscure lockdep violation for udc_mutex

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: Fix obscure lockdep violation for udc_mutex A recent commit expanding the scope of the udc_lock mutex in the gadget core managed to cause an obscure and slightly bizarre lockdep violation. In abbreviated form: ====================================================== WARNING: possible circular locking dependency detected 5.19.0-rc7+ #12510 Not tainted ------------------------------------------------------ udevadm/312 is trying to acquire lock: ffff80000aae1058 (udc_lock){+.+.}-{3:3}, at: usb_udc_uevent+0x54/0xe0 but task is already holding lock: ffff000002277548 (kn->active#4){++++}-{0:0}, at: kernfs_seq_start+0x34/0xe0 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -> #3 (kn->active#4){++++}-{0:0}:        lock_acquire+0x68/0x84        __kernfs_remove+0x268/0x380        kernfs_remove_by_name_ns+0x58/0xac        sysfs_remove_file_ns+0x18/0x24        device_del+0x15c/0x440 -> #2 (device_links_lock){+.+.}-{3:3}:        lock_acquire+0x68/0x84        __mutex_lock+0x9c/0x430        mutex_lock_nested+0x38/0x64        device_link_remove+0x3c/0xa0        _regulator_put.part.0+0x168/0x190        regulator_put+0x3c/0x54        devm_regulator_release+0x14/0x20 -> #1 (regulator_list_mutex){+.+.}-{3:3}:        lock_acquire+0x68/0x84        __mutex_lock+0x9c/0x430        mutex_lock_nested+0x38/0x64        regulator_lock_dependent+0x54/0x284        regulator_enable+0x34/0x80        phy_power_on+0x24/0x130        __dwc2_lowlevel_hw_enable+0x100/0x130        dwc2_lowlevel_hw_enable+0x18/0x40        dwc2_hsotg_udc_start+0x6c/0x2f0        gadget_bind_driver+0x124/0x1f4 -> #0 (udc_lock){+.+.}-{3:3}:        __lock_acquire+0x1298/0x20cc        lock_acquire.part.0+0xe0/0x230        lock_acquire+0x68/0x84        __mutex_lock+0x9c/0x430        mutex_lock_nested+0x38/0x64        usb_udc_uevent+0x54/0xe0 Evidently this was caused by the scope of udc_mutex being too large. The mutex is only meant to protect udc->driver along with a few other things. As far as I can tell, there's no reason for the mutex to be held while the gadget core calls a gadget driver's ->bind or ->unbind routine, or while a UDC is being started or stopped. (This accounts for link #1 in the chain above, where the mutex is held while the dwc2_hsotg_udc is started as part of driver probing.) Gadget drivers' ->disconnect callbacks are problematic. Even though usb_gadget_disconnect() will now acquire the udc_mutex, there's a window in usb_gadget_bind_driver() between the times when the mutex is released and the ->bind callback is invoked. If a disconnect occurred during that window, we could call the driver's ->disconnect routine before its ->bind routine. To prevent this from happening, it will be necessary to prevent a UDC from connecting while it has no gadget driver. This should be done already but it doesn't seem to be; currently usb_gadget_connect() has no check for this. Such a check will have to be added later. Some degree of mutual exclusion is required in soft_connect_store(), which can dereference udc->driver at arbitrary times since it is a sysfs callback. The solution here is to acquire the gadget's device lock rather than the udc_mutex. Since the driver core guarantees that the device lock is always held during driver binding and unbinding, this will make the accesses in soft_connect_store() mutually exclusive with any changes to udc->driver. Lastly, it turns out there is one place which should hold the udc_mutex but currently does not: The function_show() routine needs protection while it dereferences udc->driver. The missing lock and unlock calls are added.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2022-49943 is a Linux kernel USB gadget locking flaw. The source describes a possible circular locking dependency around udc_mutex during gadget driver binding, unbinding, UDC start/stop, and sysfs callbacks. Business urgency depends on whether your systems use USB gadget functionality; the bundle provides no CVSS, CWE, or exploitation evidence.

Executive priority

Treat as a targeted kernel maintenance item, not an emergency based on current evidence. Prioritize embedded, appliance, lab, or device-like Linux systems that rely on USB gadget behavior. Escalate if your vendor rates it higher or ties it to availability impact in your environment.

Technical view

The issue is in Linux kernel USB gadget core synchronization. udc_mutex was held across operations that could interact with regulator, device link, kernfs, and uevent locking, creating a lockdep circular dependency. The fix narrows udc_mutex scope, uses the gadget device lock for soft_connect_store, and adds missing protection in function_show.

Likely exposure

Likely exposure is limited to Linux systems running affected kernel code with USB gadget/UDC functionality. The bundle does not provide a distribution matrix, full vulnerable version range, or CPEs. General Linux servers without USB gadget use may have lower practical exposure, but this must be confirmed from kernel configuration and vendor packages.

Exploitation context

The provided sources do not show active exploitation, and KEV is false. The record describes a kernel concurrency and locking correctness issue, not an established public attack chain. No CVSS vector, CWE, exploit status, or attacker prerequisites are included in the source bundle.

Researcher notes

Evidence is limited to the CVE description and Linux stable commit references. The record lacks CVSS, CWE, CPEs, exploitability analysis, and distro-specific status. Analysis should focus on whether deployed kernels include the USB gadget core changes and whether local configurations exercise UDC binding, sysfs soft connect, or function_show paths.

Mitigation direction

  • Check vendor kernel advisories for packages containing the referenced stable commits.
  • Prioritize updates on Linux systems using USB gadget or UDC functionality.
  • Apply supported kernel updates rather than backporting manually where possible.
  • If updates are delayed, reduce unnecessary USB gadget exposure where operationally feasible.

Validation and detection

  • Inventory systems with Linux USB gadget or UDC functionality enabled.
  • Compare kernel source or package changelogs against the two referenced stable commits.
  • Confirm whether vendor kernels mark CVE-2022-49943 as fixed or not affected.
  • Include affected workflows in staging tests before production kernel rollout.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-49943 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
3Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxf44b0b95d50fffeca036e1ba36770390e0b519dd, 2191c00855b03aa59c20e698be713d952d51fc18unaffected
LinuxLinux5.19.7unaffected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.