Impact
This vulnerability is a race condition in the Linux kernel usb‑storage subsystem. During the initialization of the ene_ub6250 driver, the probe function uses usb_stor_probe2() to start the usb‑storage infrastructure and schedule a delayed scan work. While the scan work runs, both the scan path and the probe path access the same URB structure (us->current_urb) without serializing their access. The scan work serializes with us->dev_mutex, but the probe path does not, leading to a situation where usb_submit_urb() logs that the URB is already active. This race can cause erroneous warnings and potentially unstable kernel state, potentially leading to a denial of service if the kernel misbehaves under repeated contention. The weakness is a classic concurrent execution race condition (CWE-362). The impact is limited to kernel instability or service disruption and does not provide direct gain of confidentiality or integrity.
Affected Systems
All Linux kernel implementations that contain the buggy ene_ub6250 driver module are affected. No specific kernel versions are listed in the input, so any kernel that includes this source code before the fix may be vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, indicating an extremely low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires local access to a USB device that loads the ene_ub6250 driver or relies on the usb‑storage subsystem – an attacker would need to physically attach or emulate a compatible USB device to trigger the race. Exploitation would result in kernel instability or denial of service without compromising confidentiality or integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA