Executive brief
A memory leak vulnerability was identified in the Linux kernel's USB driver component. When certain USB data transfers fail, the system fails to release allocated memory, which could gradually consume system resources. This primarily affects systems using EHCI or Faraday FOTG210 USB controllers.
Technical details
A memory leak exists in the EHCI and FOTG210 USB host controller drivers within the Linux kernel. The vulnerability occurs during isochronous URB (USB Request Block) submissions; the driver allocates an 'ehci_iso_sched' structure and stores it in 'urb->hcpriv' before linking the URB to the endpoint queue. If the submission fails (e.g., the controller is inaccessible or 'usb_hcd_link_urb_to_ep' fails), the code execution jumps to a cleanup label that fails to free the staged schedule, leaving it attached to 'urb->hcpriv'. This results in a kernel memory leak. Patches have been released to ensure the schedule is freed and the pointer is cleared upon submission failure.
Affected products
- Linux Linux v6.13-rc1 to v7.1.1
Timeline
- 2026-06-30: patched: Initial patch authored by Dawei Feng
- 2026-07-25: advisory: CVE-2026-64348 published
References
- https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769
- https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb
- https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f
- https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f
- https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9
- https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2