PT-2026-64552 · Linux · Linux

CVE-2026-64331

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
usbip: vudc: fix NULL deref in vep dequeue()
vep alloc request() wasn't initializing vrequest->udc, so cancellations on the FunctionFS AIO path were arriving in vep dequeue without a valid UDC reference.
Since vrequest->udc is never actually properly used anywhere, we opt to remove it, and update vep dequeue to obtain a reference to the udc with ep to vudc(), consistent with the other vep ops.
AFAICT this bug has existed for ~10 years. Seems that nobody has really stressed the FunctionFS AIO path on usbip's vudc.
I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints via AIO. Before the fix, running usbip attach from the host would cause the guest to oops with the following backtrace:
Call trace: vep dequeue+0x1c/0xe4 (P) usb ep dequeue+0x14/0x20 ffs aio cancel+0x24/0x34 arm64 sys io cancel+0xb0/0x124 do el0 svc+0x68/0x100 el0 svc+0x18/0x5c el0t 64 sync handler+0x98/0xdc el0t 64 sync+0x154/0x158
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64331

Affected Products

Linux