PT-2026-64558 · Linux · Linux

CVE-2026-64337

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
usb: mtu3: unmap request DMA on queue failure
mtu3 gadget queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3 prepare transfer() fails.
Normal completion and dequeue paths unmap requests from mtu3 req complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64337

Affected Products

Linux