-

CVE-2026-97483

usb: core: hcd: fix possible deadlock in rh control transfers

In the Linux kernel, the following vulnerability has been resolved:

usb: core: hcd: fix possible deadlock in rh control transfers

>From within the SCSI error handler memory allocations must not
trigger IO. Handling errors in UAS and the storage driver may
involve resetting a device. The thread doing the reset itself
relies on VM magic. However, that is insufficient, as resetting
a device involves resuming it. Resumption as well as resetting
involves conrol transfers to the parent of the device to be reset.
That may be a root hub. Hence usbcore must heed the flags passed
to usb_submit_urb() processing control transfers to root hubs.

The problem exist since the storage driver has been merged.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < 8461eda5af77c44d216cec66455bd5b01ee35c9a
Status affected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < 8f82fc3d72e5feb7a1efae94b51b431c5bf41c86
Status affected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < 936b08d87c667031725bcc753007e7c1182548c6
Status affected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < d0291fb4d91982d9f6a680bf759ff0555d351ecb
Status affected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < fff917c85d37a294397c5440a795591ca9d6b602
Status affected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < 549672a3fb6b36ea408238f89ecf9f41d2da6225
Status affected
Version e57e780b346a7277fdd3bde765d9d8728b99bfa1
Version < d5559f43d76b398392b26a15cbc16d731969cd1c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.12
Status affected
Version 0
Version < 3.12
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fff917c85d37a294397c5440a795591ca9d6b602
https://git.kernel.org/stable/c/549672a3fb6b36ea408238f89ecf9f41d2da6225
https://git.kernel.org/stable/c/d5559f43d76b398392b26a15cbc16d731969cd1c
https://git.kernel.org/stable/c/8461eda5af77c44d216cec66455bd5b01ee35c9a
https://git.kernel.org/stable/c/8f82fc3d72e5feb7a1efae94b51b431c5bf41c86
https://git.kernel.org/stable/c/936b08d87c667031725bcc753007e7c1182548c6
https://git.kernel.org/stable/c/d0291fb4d91982d9f6a680bf759ff0555d351ecb