CVE-2025-38404

Updated on 25 Jul 2025

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: displayport: Fix potential deadlock

The deadlock can occur due to a recursive lock acquisition of cros_typec_altmode_data::mutex. The call chain is as follows:

  1. cros_typec_altmode_work() acquires the mutex
  2. typec_altmode_vdm() -> dp_altmode_vdm() ->
  3. typec_altmode_exit() -> cros_typec_altmode_exit()
  4. cros_typec_altmode_exit() attempts to acquire the mutex again

To prevent this, defer the typec_altmode_exit() call by scheduling it rather than calling it directly from within the mutex-protected context.

Details

Affected product:
Oracle Linux 7 ELS
Affected packages:
kernel @ 3.10.0 (+1 more)

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: displayport: Fix potential deadlock

The deadlock can occur due to a recursive lock acquisition of cros_typec_altmode_data::mutex. The call chain is as follows:

  1. cros_typec_altmode_work() acquires the mutex
  2. typec_altmode_vdm() -> dp_altmode_vdm() ->
  3. typec_altmode_exit() -> cros_typec_altmode_exit()
  4. cros_typec_altmode_exit() attempts to acquire the mutex again

To prevent this, defer the typec_altmode_exit() call by scheduling it rather than calling it directly from within the mutex-protected context.

Fixes