« Volver al listado

CVE-2026-80826

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

USB: c67x00: fix use-after-free in c67x00_add_iso_urb()

When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state.

c67x00_giveback_urb() frees the URB private data, and the completion callback may release the final URB reference. The following accesses to urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed memory.

Update next_frame and cnt before giving back the failed final packet, making the giveback the last operation that uses the URB and its private data.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80826",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "e4039e9bebb528dd9cd7ac72aeaec529c26c355a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "ade18b4ce78a16558f4f435aece80082f6f7b64c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "bb572801290e25ec1c4753d14af35777303f5d6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "62cd519ab74cac499036cd88c11692f8f0d53e14",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "ff172092cba7ec990ecc7b610ce703e19570b8f0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "7983daa159981fac125db2457437723f38ea1472",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "f24dcc61bd0ecf7639fac5bf700450b398d793a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d",
              "lessThan": "b1e24de475bf2d66fffc9103f3444b783527d55a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/c67x00/c67x00-sched.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.26"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.26",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.269",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.220",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.187",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.49",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.13",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/c67x00/c67x00-sched.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:10.543",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/62cd519ab74cac499036cd88c11692f8f0d53e14",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7983daa159981fac125db2457437723f38ea1472",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ade18b4ce78a16558f4f435aece80082f6f7b64c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b1e24de475bf2d66fffc9103f3444b783527d55a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bb572801290e25ec1c4753d14af35777303f5d6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e4039e9bebb528dd9cd7ac72aeaec529c26c355a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f24dcc61bd0ecf7639fac5bf700450b398d793a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff172092cba7ec990ecc7b610ce703e19570b8f0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: c67x00: fix use-after-free in c67x00_add_iso_urb()\n\nWhen TD creation fails for the last packet of an isochronous URB,\nc67x00_add_iso_urb() gives the URB back before updating the endpoint\nscheduling state.\n\nc67x00_giveback_urb() frees the URB private data, and the completion\ncallback may release the final URB reference. The following accesses to\nurbp->ep_data, urb->interval, and urbp->cnt can therefore use freed\nmemory.\n\nUpdate next_frame and cnt before giving back the failed final packet,\nmaking the giveback the last operation that uses the URB and its private\ndata."
    }
  ],
  "lastModified": "2026-09-04T16:18:10.543",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}