Impact
The cxacru_cm() routine in the Linux USB ATM driver fails to terminate the receive USB request block (rcv_urb) when an error occurs during submission or waiting for the send request (snd_urb). The rcv_urb remains active and over time may be re‑submitted during initialization, which triggers a warning in usb_submit_urb() and could lead to kernel instability or a crash if the faulty URB is repeatedly processed. This flaw represents an improper resource cleanup that can leave the driver in an inconsistent state.
Affected Systems
All kernel installations that include the cxacru USB ATM driver before the fix are potentially affected. The issue is present in any Linux kernel version that ships the unpatched driver module, regardless of distribution or kernel flavor.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS score is less than 1%, indicating a moderate severity and a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack would require local or physical access to the system hosting a USB ATM device, as the flaw is triggered during driver initialization of the device.
OpenCVE Enrichment
Debian DLA
Debian DSA