Junglewise Threat Intelligence

CVE-2026-63927: Linux Kernel use after free in dwc2 USB driver debug code

CVE-2026-63927 · Severity: info · CVSS 2.1 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB driver for DWC2 controllers. This issue occurs in debug code and could potentially lead to a system crash or instability when a USB device is disconnected or its request is cancelled. Because it requires local access or physical interaction with the device, the risk to most remote operations is low.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/usb/dwc2/hcd.c within the _dwc2_hcd_urb_dequeue function. The root cause is a dereference of the 'urb' structure for a debug message after it has been passed to usb_hcd_giveback_urb(), at which point the memory may have been freed or reused. An attacker could trigger this by dequeuing a URB, leading to a kernel oops or unpredictable behavior if debug logging is enabled. The fix involves caching the urb->status value before the giveback call. Patches have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.10 to 6.6.143

Timeline

  • 2026-05-20: other: Vulnerability fixed in source code by Dan Carpenter
  • 2026-07-19: disclosed: CVE published

References

Related threats