Executive brief
A vulnerability was identified in the Linux kernel's USB driver for DWC2 controllers. This issue occurs in debug code and could potentially lead to a system crash or instability when a USB device is disconnected or its request is cancelled. Because it requires local access or physical interaction with the device, the risk to most remote operations is low.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/usb/dwc2/hcd.c within the _dwc2_hcd_urb_dequeue function. The root cause is a dereference of the 'urb' structure for a debug message after it has been passed to usb_hcd_giveback_urb(), at which point the memory may have been freed or reused. An attacker could trigger this by dequeuing a URB, leading to a kernel oops or unpredictable behavior if debug logging is enabled. The fix involves caching the urb->status value before the giveback call. Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.10 to 6.6.143
Timeline
- 2026-05-20: other: Vulnerability fixed in source code by Dan Carpenter
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0584af4fe40fa5e254a05d69ce658746de641708
- https://git.kernel.org/stable/c/63b0dafa676aad4d0c3f01a61ad8e2990907660c
- https://git.kernel.org/stable/c/6d0b79d1d1118145e48a68192b6d733e39387053
- https://git.kernel.org/stable/c/84ea928ed584756e59c6ac09736f12d1db95ded0
- https://git.kernel.org/stable/c/9ea06a3fbf9f16e0d98c52cb3b99642be15ec281
- https://git.kernel.org/stable/c/9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913
- https://git.kernel.org/stable/c/a15eeeceb94cbc04edef395e4d777ff554bdc27d