Executive brief
A vulnerability was identified in the Linux kernel's MediaTek USB3 driver where system memory mappings were not properly cleaned up during certain error conditions. This component is responsible for managing USB connections on devices using specific MediaTek hardware. If an error occurs while queuing a data transfer, the system fails to release the associated memory mapping, which could lead to resource exhaustion or system instability over time.
Technical details
A memory management vulnerability exists in the Linux kernel mtu3 USB driver (drivers/usb/mtu3/mtu3_gadget.c). The function mtu3_gadget_queue() performs DMA mapping for a request before verifying if the QMU GPD ring can accept the transfer. If mtu3_prepare_transfer() fails, the function returns -EAGAIN without unmapping the DMA request. Because this error path bypasses the standard mtu3_req_complete() helper, the DMA mapping remains active, leading to a resource leak. The issue has been resolved by adding a call to usb_gadget_unmap_request() in the affected error path.
Affected products
- Linux Linux Kernel 4.10 to 5.10.261, 5.15.212, 6.1.101, 6.6.41, 6.9.10, 6.10.0
Timeline
- 2026-06-23: disclosed: Patch submitted by Haoxiang Li
- 2026-07-25: advisory: CVE published in NVD dataset
- 2026-07-18: patched: Fix committed to stable kernel tree
References
- https://git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09
- https://git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c
- https://git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98
- https://git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236
- https://git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74
- https://git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1
- https://git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5