« Volver al listado

CVE-2026-93118

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: aspeed_udc: check endpoint DMA allocation

ast_udc_probe() allocates a coherent DMA buffer used as the backing store for endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer pointers from udc->ep0_buf, so a failed allocation is dereferenced during probe.

Check the allocation before endpoint setup. The existing probe error path called ast_udc_remove(), which unregisters the gadget unconditionally and is not safe before usb_add_gadget_udc() succeeds. Add a local cleanup helper for probe failures so pre-registration failures only unwind the resources that were actually initialized.

Leer descripción completaMostrar menos

This was found by a local static analysis checker for unchecked allocator returns while scanning Linux 6.16. The change was checked by applying it to current mainline and by running checkpatch. I do not have access to Aspeed UDC hardware, so no runtime testing was performed.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93118",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "055276c1320564b0192b3af323b8cc67f9b665e1",
              "lessThan": "d7ae1a48e70e9c3451b7dc7bc3896c82884bc4df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "055276c1320564b0192b3af323b8cc67f9b665e1",
              "lessThan": "4aaad88f857498ed1294f061f0b25d27ae891c55",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "055276c1320564b0192b3af323b8cc67f9b665e1",
              "lessThan": "6182e708e2e1f55521c8a01d7535630ecc2d7df9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "055276c1320564b0192b3af323b8cc67f9b665e1",
              "lessThan": "ff6e88e29965bd06f640e59acdcf0bbf04a7f55c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "055276c1320564b0192b3af323b8cc67f9b665e1",
              "lessThan": "9e6f57107c1886052d4baaa047a2bc3d0e91be5d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "055276c1320564b0192b3af323b8cc67f9b665e1",
              "lessThan": "97cee53a94be3bd4fd8fbed6071bd2f32dad1ab1",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/gadget/udc/aspeed_udc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/gadget/udc/aspeed_udc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:06.427",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4aaad88f857498ed1294f061f0b25d27ae891c55",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6182e708e2e1f55521c8a01d7535630ecc2d7df9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/97cee53a94be3bd4fd8fbed6071bd2f32dad1ab1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9e6f57107c1886052d4baaa047a2bc3d0e91be5d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7ae1a48e70e9c3451b7dc7bc3896c82884bc4df",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff6e88e29965bd06f640e59acdcf0bbf04a7f55c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: aspeed_udc: check endpoint DMA allocation\n\nast_udc_probe() allocates a coherent DMA buffer used as the backing store\nfor endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer\npointers from udc->ep0_buf, so a failed allocation is dereferenced during\nprobe.\n\nCheck the allocation before endpoint setup. The existing probe error path\ncalled ast_udc_remove(), which unregisters the gadget unconditionally and\nis not safe before usb_add_gadget_udc() succeeds. Add a local cleanup\nhelper for probe failures so pre-registration failures only unwind the\nresources that were actually initialized.\n\nThis was found by a local static analysis checker for unchecked allocator\nreturns while scanning Linux 6.16. The change was checked by applying it\nto current mainline and by running checkpatch. I do not have access to\nAspeed UDC hardware, so no runtime testing was performed."
    }
  ],
  "lastModified": "2026-09-17T17:18:06.427",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}