PT-2026-36389 · Linux · Linux Kernel

CVE-2026-31754

·

Published

2026-04-01

·

Updated

2026-07-31

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A state inconsistency occurs in the cdns3 USB driver when cdns3 gadget start() fails. In this scenario, the Dual-Role Device (DRD) hardware remains in gadget mode while the software state is marked as INACTIVE. If a user attempts to switch to host mode via the sysfs endpoint '/sys/class/usb role/13180000.usb-role-switch/role', the cdns role stop() function skips the necessary cleanup because the state is still INACTIVE. This violation of the DRD controller design specification can lead to a synchronous external abort in the xhci gen setup() function during host controller setup.
Recommendations Apply the fix that implements a call to the cdns drd gadget off() function in the error path to ensure the DRD gadget state is properly cleaned up.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10909
CVE-2026-31754
ECHO-8321-D172-CE83
OESA-2026-2416
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4

Affected Products

Linux Kernel