Executive brief
A vulnerability in the Linux kernel's USB-over-IP (USBIP) virtual device controller could allow a local user to crash the system. The issue occurs when certain USB operations are cancelled, leading to a system 'oops' or kernel panic. This primarily affects systems using the FunctionFS asynchronous I/O path within USBIP environments.
Technical details
A NULL pointer dereference exists in the 'vep_dequeue' function within 'drivers/usb/usbip/vudc_dev.c'. The root cause is that 'vep_alloc_request' failed to initialize the 'vrequest->udc' pointer. When cancellations occur on the FunctionFS AIO path, 'vep_dequeue' attempts to reference this uninitialized pointer, resulting in a kernel oops. The fix involves removing the unused 'udc' field from the 'vrequest' structure and instead obtaining the UDC reference via 'ep_to_vudc(ep)', ensuring consistency with other virtual endpoint operations. This bug has reportedly existed for approximately 10 years.
Affected products
- Linux Linux Kernel b6a0ca111867 to 9858c91d9ee6a13c45311569039413729fc9b757
Timeline
- 2026-06-26: other: Patch authored
- 2026-07-25: disclosed: CVE published
- 2026-07-18: patched: Commits applied to stable branches
References
- https://git.kernel.org/stable/c/0025276175fbbe0dcbf3f84d090b0adee769e9d9
- https://git.kernel.org/stable/c/0443e4416aa1ee97748d1ed904eaf3352c60045e
- https://git.kernel.org/stable/c/1226293ec9bed3d4cc5b05eeeb811d315ca51652
- https://git.kernel.org/stable/c/347b59e9f96719d89b6ef555d02a18ada1a5846f
- https://git.kernel.org/stable/c/3750f75f29f99c0223601e2ee73ad084adec47bd
- https://git.kernel.org/stable/c/9858c91d9ee6a13c45311569039413729fc9b757
- https://git.kernel.org/stable/c/c5371e0b91b24159a3ebaa61e70b0980bcf03c0a