CVE-2026-23188
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/02/2026
Last modified:
14/02/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: usb: r8152: fix resume reset deadlock<br />
<br />
rtl8152 can trigger device reset during reset which<br />
potentially can result in a deadlock:<br />
<br />
**** DPM device timeout after 10 seconds; 15 seconds until panic ****<br />
Call Trace:<br />
<br />
schedule+0x483/0x1370<br />
schedule_preempt_disabled+0x15/0x30<br />
__mutex_lock_common+0x1fd/0x470<br />
__rtl8152_set_mac_address+0x80/0x1f0<br />
dev_set_mac_address+0x7f/0x150<br />
rtl8152_post_reset+0x72/0x150<br />
usb_reset_device+0x1d0/0x220<br />
rtl8152_resume+0x99/0xc0<br />
usb_resume_interface+0x3e/0xc0<br />
usb_resume_both+0x104/0x150<br />
usb_resume+0x22/0x110<br />
<br />
The problem is that rtl8152 resume calls reset under<br />
tp->control mutex while reset basically re-enters rtl8152<br />
and attempts to acquire the same tp->control lock once<br />
again.<br />
<br />
Reset INACCESSIBLE device outside of tp->control mutex<br />
scope to avoid recursive mutex_lock() deadlock.



