{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()  ueagle-atm uses the asynchronous request_firmware_nowait() in .probe(), but does not wait for its completion, not even in .disconnect(); so, if the device is unplugged meanwhile, its teardown runs concurrently with that.  Even though this inconsistency is worth addressing on its own, it has also triggered several bug reports in syzbot over the years (some auto-closed) where the firmware sysfs fallback mechanism (CONFIG_FW_LOADER_USER_HELPER) creates a firmware subdirectory in the device directory during its removal, which might hit unexpected conditions in kernfs, apparently, depending at which point the add and remove operations raced. (See links.)  The pattern is:  usb ?-?: Direct firmware load for ueagle-atm/eagle?.fw failed with error -2 usb ?-?: Falling back to sysfs fallback for: ueagle-atm/eagle?.fw \u003cERROR\u003e Call trace:  ...  kernfs_create_dir_ns  sysfs_create_dir_ns  create_dir  kobject_add_internal  kobject_add_varg  kobject_add  class_dir_create_and_add  get_device_parent  device_add  fw_load_sysfs_fallback  fw_load_from_user_helper  firmware_fallback_sysfs  _request_firmware  request_firmware_work_func  ...  (Some variations are observed, after fw_load_sysfs_fallback(), e.g., [1].)  While the kernfs side is being looked at, the ueagle-atm side can be fixed by waiting for the pre-firmware load in the .disconnect() handler.  This change has a similar approach to previous work by Andrey Tsygunka [2] (wait_for_completion() in .disconnect()), but it is relatively different in design/implementation; using the Originally-by tag for credit assignment.  This has been tested with: - synthetic reproducer to check the error path; - USB gadget (virtual device) to check the firmware upload path; - QEMU device emulator to check the device ID re-enumeration path; (The latter two were written by Claude; no other code/text in this commit.)  Links (year first reported):  2025 https://syzbot.org/bug?extid=ce1e5a1b4e086b43e56d  2025 https://syzbot.org/bug?extid=9af8471255ac36e34fd4  2024 https://syzbot.org/bug?extid=306212936b13e520679d  2023 https://syzkaller.appspot.com/bug?extid=457452d30bcdda75ead2  2022 https://syzbot.org/bug?extid=782984d6f1701b526edb  2021 https://syzbot.org/bug?id=f3f221579f4ef7e9691281f3c6f56c05f83e8490  2021 https://syzbot.org/bug?id=84d86f0d71394829df6fc53daf6642c045983881  2021 https://syzbot.org/bug?id=3302dc1c0e2b9c94f2e8edb404eabc9267bc6f90  [1] https://syzkaller.appspot.com/bug?extid=457452d30bcdda75ead2 [2] https://lore.kernel.org/lkml/20250410093146.3776801-2-aitsygunka@yandex.ru/",
  "id": "DEBIAN-CVE-2026-68456",
  "modified": "2026-09-14T16:47:29.501870160Z",
  "published": "2026-08-15T06:17:32.713Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-68456"
    }
  ],
  "upstream": [
    "CVE-2026-68456"
  ]
}