PT-2026-64552 · Linux · Linux
CVE-2026-64331
·
Published
2026-07-25
·
Updated
2026-07-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
usbip: vudc: fix NULL deref in vep dequeue()
vep alloc request() wasn't initializing vrequest->udc, so cancellations
on the FunctionFS AIO path were arriving in vep dequeue without a valid
UDC reference.
Since vrequest->udc is never actually properly used anywhere, we opt to
remove it, and update vep dequeue to obtain a reference to the udc with
ep to vudc(), consistent with the other vep ops.
AFAICT this bug has existed for ~10 years. Seems that nobody has really
stressed the FunctionFS AIO path on usbip's vudc.
I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints
via AIO. Before the fix, running
usbip attach from the host would
cause the guest to oops with the following backtrace:Call trace:
vep dequeue+0x1c/0xe4 (P)
usb ep dequeue+0x14/0x20
ffs aio cancel+0x24/0x34
arm64 sys io cancel+0xb0/0x124
do el0 svc+0x68/0x100
el0 svc+0x18/0x5c
el0t 64 sync handler+0x98/0xdc
el0t 64 sync+0x154/0x158
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux