Description
In the Linux kernel, the following vulnerability has been resolved:

usb-storage: ene_ub6250: fix race between scan work and probe

ene_ub6250_probe() calls usb_stor_probe2(), which starts the usb-storage
infrastructure and schedules the delayed scan work. The driver then
calls ene_get_card_type(), which sends an ENE command through
ene_send_scsi_cmd() and the usb-storage bulk transfer helpers.

Both the delayed scan work, through usb_stor_Bulk_max_lun(), and
ene_get_card_type() use us->current_urb. The scan work serializes this
access with us->dev_mutex, but the ENE card-type probe does not. If the
scan work runs while ene_get_card_type() is still using us->current_urb,
usb_submit_urb() warns that the URB is already active.

Serialize ene_get_card_type() with us->dev_mutex, matching the locking
used by the scan path.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

This vulnerability is a race condition in the Linux kernel usb‑storage subsystem. During the initialization of the ene_ub6250 driver, the probe function uses usb_stor_probe2() to start the usb‑storage infrastructure and schedule a delayed scan work. While the scan work runs, both the scan path and the probe path access the same URB structure (us->current_urb) without serializing their access. The scan work serializes with us->dev_mutex, but the probe path does not, leading to a situation where usb_submit_urb() logs that the URB is already active. This race can cause erroneous warnings and potentially unstable kernel state, potentially leading to a denial of service if the kernel misbehaves under repeated contention. The weakness is a classic concurrent execution race condition (CWE-362). The impact is limited to kernel instability or service disruption and does not provide direct gain of confidentiality or integrity.

Affected Systems

All Linux kernel implementations that contain the buggy ene_ub6250 driver module are affected. No specific kernel versions are listed in the input, so any kernel that includes this source code before the fix may be vulnerable.

Risk and Exploitability

The EPSS score is less than 1%, indicating an extremely low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires local access to a USB device that loads the ene_ub6250 driver or relies on the usb‑storage subsystem – an attacker would need to physically attach or emulate a compatible USB device to trigger the race. Exploitation would result in kernel instability or denial of service without compromising confidentiality or integrity.

Generated by OpenCVE AI on September 18, 2026 at 07:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the ene_ub6250 race‑condition fix, such as the most recent stable Linux kernel release; the patch is referenced in the commit history provided. Reboot the system after the kernel upgrade to ensure the new module is loaded. If an immediate kernel upgrade is not feasible, disable or blacklist the ene_ub6250 driver using udev rules or modprobe.conf to prevent the driver from loading until the patch can be applied.

Generated by OpenCVE AI on September 18, 2026 at 07:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb-storage: ene_ub6250: fix race between scan work and probe ene_ub6250_probe() calls usb_stor_probe2(), which starts the usb-storage infrastructure and schedules the delayed scan work. The driver then calls ene_get_card_type(), which sends an ENE command through ene_send_scsi_cmd() and the usb-storage bulk transfer helpers. Both the delayed scan work, through usb_stor_Bulk_max_lun(), and ene_get_card_type() use us->current_urb. The scan work serializes this access with us->dev_mutex, but the ENE card-type probe does not. If the scan work runs while ene_get_card_type() is still using us->current_urb, usb_submit_urb() warns that the URB is already active. Serialize ene_get_card_type() with us->dev_mutex, matching the locking used by the scan path.
Title usb-storage: ene_ub6250: fix race between scan work and probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:27.632Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90031

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:16.177

Modified: 2026-09-17T10:17:06.040

Link: CVE-2026-90031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')