CVE-2025-23151: Debian Linux
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix race between unprepare and queue_buf A client driver may use mhi_unprepare_from_transfer() to quiesce incoming data during the client driver's tear down. The client driver might also be processing data at the same time, resulting in a call to mhi_queue_buf() which will invoke mhi_gen_tre(). If mhi_gen_tre() runs after mhi_unprepare_from_transfer() has torn down the channel, a panic will occur due to an invalid dereference leading to a page fault. This occurs because mhi_gen_tre() does not verify the channel state after locking it. Fix this by having mhi_gen_tre() confirm the channel state is valid, or return error to avoid accessing deinitialized data. [mani: added stable tag]
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 5.15.149, before 5.15.181 (fixed in 5.15.181); from 6.1.76, before 6.1.135 (fixed in 6.1.135); from 6.6.15, before 6.6.88 (fixed in 6.6.88); from 6.7.3, before 6.12.24 (fixed in 6.12.24); from 6.13, before 6.13.12 (fixed in 6.13.12); from 6.14, before 6.14.3 (fixed in 6.14.3)
Published 2025-05-01. Last modified 2026-07-30.