Junglewise Threat Intelligence

CVE-2026-64331: Linux Kernel NULL pointer dereference in usbip vudc

CVE-2026-64331 · Severity: info · CVSS 5.5 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB-over-IP (USBIP) virtual device controller could allow a local user to crash the system. The issue occurs when certain USB operations are cancelled, leading to a system 'oops' or kernel panic. This primarily affects systems using the FunctionFS asynchronous I/O path within USBIP environments.

Technical details

A NULL pointer dereference exists in the 'vep_dequeue' function within 'drivers/usb/usbip/vudc_dev.c'. The root cause is that 'vep_alloc_request' failed to initialize the 'vrequest->udc' pointer. When cancellations occur on the FunctionFS AIO path, 'vep_dequeue' attempts to reference this uninitialized pointer, resulting in a kernel oops. The fix involves removing the unused 'udc' field from the 'vrequest' structure and instead obtaining the UDC reference via 'ep_to_vudc(ep)', ensuring consistency with other virtual endpoint operations. This bug has reportedly existed for approximately 10 years.

Affected products

  • Linux Linux Kernel b6a0ca111867 to 9858c91d9ee6a13c45311569039413729fc9b757

Timeline

  • 2026-06-26: other: Patch authored
  • 2026-07-25: disclosed: CVE published
  • 2026-07-18: patched: Commits applied to stable branches

References

Related threats