CVE-2026-64454
In the Linux kernel, the following vulnerability has been resolved:
usb: dwc3: run gadget disconnect from sleepable suspend context
dwc3_gadget_suspend() takes dwc->lock with IRQs disabled and then calls dwc3_disconnect_gadget(). For async callbacks that helper only uses plain spin_unlock()/spin_lock(), so the gadget ->disconnect() callback still runs with IRQs disabled and any sleepable callback trips Lockdep.
This issue was found by our static analysis tool and then manually reviewed against the current tree.
The grounded PoC kept the dwc3_gadget_suspend() -> dwc3_disconnect_gadget() -> gadget_driver->disconnect() chain, and Lockdep reported:
Leer descripción completaMostrar menos
Keep the disconnect callback selection in one common helper, but add a sleepable suspend-side wrapper which snapshots the callback under dwc->lock and then runs it after spin_unlock_irqrestore(). The regular event path still uses the existing spin_unlock()/spin_lock() window.
Detalles técnicos trazas, registros y código del informe original
BUG: sleeping function called from invalid context gadget_disconnect+0x21/0x39 [vuln_msv] dwc3_gadget_suspend.constprop.0+0x2b/0x42 [vuln_msv]
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/010382937fb69892b3469ac4d30af072262f59e8
- https://git.kernel.org/stable/c/48958478cb8dbc429a5b19f36e866b63d6297d1d
- https://git.kernel.org/stable/c/5e5798880eb1533a7de6fb68eb14b2d8202ebf76
- https://git.kernel.org/stable/c/642e04f5c292d04070ae6e4374fbf14cc40a2465
- https://git.kernel.org/stable/c/b399be2958456efe1b64b19c55a54a24e9035769
- https://git.kernel.org/stable/c/c4e232bd07fe2b69a6e5c380db41dd36b95e0524
- https://git.kernel.org/stable/c/e0e4f15d4225fb7156cc0e3c21eb8953114f9b89
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64454",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "20351ddb1f41cfb3ae20e105425ef43a28393d76",
"lessThan": "b399be2958456efe1b64b19c55a54a24e9035769",
"versionType": "git"
},
{
"status": "affected",
"version": "ad43004fd5326bec4466ecc8a07fe0e570b553ca",
"lessThan": "48958478cb8dbc429a5b19f36e866b63d6297d1d",
"versionType": "git"
},
{
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"lessThan": "5e5798880eb1533a7de6fb68eb14b2d8202ebf76",
"versionType": "git"
},
{
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"lessThan": "e0e4f15d4225fb7156cc0e3c21eb8953114f9b89",
"versionType": "git"
},
{
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"lessThan": "c4e232bd07fe2b69a6e5c380db41dd36b95e0524",
"versionType": "git"
},
{
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"lessThan": "642e04f5c292d04070ae6e4374fbf14cc40a2465",
"versionType": "git"
},
{
"status": "affected",
"version": "c8540870af4ce6ddeb27a7bb5498b75fb29b643c",
"lessThan": "010382937fb69892b3469ac4d30af072262f59e8",
"versionType": "git"
},
{
"status": "affected",
"version": "06684c72b6b153dc434bb6ccebbb49f4cd812b5e",
"versionType": "git"
},
{
"status": "affected",
"version": "5.15.128",
"lessThan": "5.15.212",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.30",
"lessThan": "6.1.178",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.3.4",
"lessThan": "6.4",
"versionType": "semver"
}
],
"programFiles": [
"drivers/usb/dwc3/gadget.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/usb/dwc3/gadget.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-25T10:17:30.407",
"references": [
{
"url": "https://git.kernel.org/stable/c/010382937fb69892b3469ac4d30af072262f59e8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/48958478cb8dbc429a5b19f36e866b63d6297d1d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e5798880eb1533a7de6fb68eb14b2d8202ebf76",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/642e04f5c292d04070ae6e4374fbf14cc40a2465",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b399be2958456efe1b64b19c55a54a24e9035769",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c4e232bd07fe2b69a6e5c380db41dd36b95e0524",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e0e4f15d4225fb7156cc0e3c21eb8953114f9b89",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: run gadget disconnect from sleepable suspend context\n\ndwc3_gadget_suspend() takes dwc->lock with IRQs disabled and then calls\ndwc3_disconnect_gadget(). For async callbacks that helper only uses\nplain spin_unlock()/spin_lock(), so the gadget ->disconnect() callback\nstill runs with IRQs disabled and any sleepable callback trips Lockdep.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the dwc3_gadget_suspend() ->\ndwc3_disconnect_gadget() -> gadget_driver->disconnect() chain, and\nLockdep reported:\n\n BUG: sleeping function called from invalid context\n gadget_disconnect+0x21/0x39 [vuln_msv]\n dwc3_gadget_suspend.constprop.0+0x2b/0x42 [vuln_msv]\n\nKeep the disconnect callback selection in one common helper, but add a\nsleepable suspend-side wrapper which snapshots the callback under\ndwc->lock and then runs it after spin_unlock_irqrestore(). The regular\nevent path still uses the existing spin_unlock()/spin_lock() window."
}
],
"lastModified": "2026-08-17T05:17:50.467",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}