« Volver al listado

CVE-2026-64348

Estado: AnalizadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

usb: free iso schedules on failed submit

EHCI and FOTG210 isochronous submits build an ehci_iso_sched before linking the URB to the endpoint queue, and keep the staged schedule in urb->hcpriv until iso_stream_schedule() and the link helpers consume it. If the controller is no longer accessible, or usb_hcd_link_urb_to_ep() fails, submit jumps to done_not_linked before that handoff happens and leaks the staged schedule still attached to urb->hcpriv.

Free the staged schedule from done_not_linked when submit fails before the URB is linked and clear urb->hcpriv after the free.

Leer descripción completaMostrar menos

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have an EHCI host controller with a USB isochronous device to test with, no runtime testing was able to be performed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de fuga de memoria en kernel Linux (CWE-416 Use-After-Free) con acceso local (AV:L) y privilegios de usuario (PR:L). La explotación potencial permite escalada mediante corrupción de memoria del controlador USB EHCI.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64348",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8de98402652c01839ae321be6cb3054cf5735d83",
              "lessThan": "b0d00d077f9738d215af9b50c74dffab7a1de19f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8de98402652c01839ae321be6cb3054cf5735d83",
              "lessThan": "be5004395dfd0b6ec310db359f887fa396fd0dd2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8de98402652c01839ae321be6cb3054cf5735d83",
              "lessThan": "8890699eea19027ef6e4f9cbcf27cba5e789793f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8de98402652c01839ae321be6cb3054cf5735d83",
              "lessThan": "6bc17a78a05671d303820224fb37ca339c1dc2cb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8de98402652c01839ae321be6cb3054cf5735d83",
              "lessThan": "4bb88aee6b868cbf73bf453f62497802f5fe4769",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8de98402652c01839ae321be6cb3054cf5735d83",
              "lessThan": "b9399d25fbb34a05bbe76eeedd730f62ff2670e9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/fotg210/fotg210-hcd.c",
            "drivers/usb/host/ehci-sched.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/fotg210/fotg210-hcd.c",
            "drivers/usb/host/ehci-sched.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-25T10:17:17.040",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: free iso schedules on failed submit\n\nEHCI and FOTG210 isochronous submits build an ehci_iso_sched before\nlinking the URB to the endpoint queue, and keep the staged schedule in\nurb->hcpriv until iso_stream_schedule() and the link helpers consume it.\nIf the controller is no longer accessible, or usb_hcd_link_urb_to_ep()\nfails, submit jumps to done_not_linked before that handoff happens and\nleaks the staged schedule still attached to urb->hcpriv.\n\nFree the staged schedule from done_not_linked when submit fails before\nthe URB is linked and clear urb->hcpriv after the free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nEHCI host controller with a USB isochronous device to test with, no\nruntime testing was able to be performed."
    }
  ],
  "lastModified": "2026-09-03T16:03:56.440",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00AF9AA6-CEBA-4198-A7F6-298DA167062C",
              "versionEndExcluding": "5.10.261",
              "versionStartIncluding": "2.6.15.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA9CEC46-431F-4DB2-AFC6-D1CE68AD27CA",
              "versionEndExcluding": "6.6.145",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38A8100E-2B1A-462F-AEE9-8901B870FEF2",
              "versionEndExcluding": "6.12.96",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
              "versionEndExcluding": "6.18.39",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
              "versionEndExcluding": "7.1.4",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:2.6.15:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7623CAC-67FF-477D-9F80-F383014C82DC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A89DC9CD-C06F-4B9B-B376-900E65016296"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15BED7A7-3E96-43EF-8B6F-3C94897C3AA1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6FCAC4-B6C6-4125-B3AC-F30407AA7738"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "707ECC75-65B6-4B02-BE85-A4804549A2DD"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E8B9085-7ADB-4A05-89EF-12949B6A0509"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FC0D50D-9D58-4947-A197-A5A3FF07E7E3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}