-

CVE-2026-64348

usb: free iso schedules on failed submit

In the Linux kernel, the following vulnerability has been resolved:

usb: free iso schedules on failed submit

EHCI and FOTG210 isochronous submits build an ehci_iso_sched before
linking the URB to the endpoint queue, and keep the staged schedule in
urb->hcpriv until iso_stream_schedule() and the link helpers consume it.
If the controller is no longer accessible, or usb_hcd_link_urb_to_ep()
fails, submit jumps to done_not_linked before that handoff happens and
leaks the staged schedule still attached to urb->hcpriv.

Free the staged schedule from done_not_linked when submit fails before
the URB is linked and clear urb->hcpriv after the free.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have an
EHCI host controller with a USB isochronous device to test with, no
runtime testing was able to be performed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 8de98402652c01839ae321be6cb3054cf5735d83
Version < b0d00d077f9738d215af9b50c74dffab7a1de19f
Status affected
Version 8de98402652c01839ae321be6cb3054cf5735d83
Version < be5004395dfd0b6ec310db359f887fa396fd0dd2
Status affected
Version 8de98402652c01839ae321be6cb3054cf5735d83
Version < 8890699eea19027ef6e4f9cbcf27cba5e789793f
Status affected
Version 8de98402652c01839ae321be6cb3054cf5735d83
Version < 6bc17a78a05671d303820224fb37ca339c1dc2cb
Status affected
Version 8de98402652c01839ae321be6cb3054cf5735d83
Version < 4bb88aee6b868cbf73bf453f62497802f5fe4769
Status affected
Version 8de98402652c01839ae321be6cb3054cf5735d83
Version < b9399d25fbb34a05bbe76eeedd730f62ff2670e9
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.15
Status affected
Version 0
Version < 2.6.15
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f
https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2
https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f
https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb
https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769
https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9