CVE-2026-97483
In the Linux kernel, the following vulnerability has been resolved:
usb: core: hcd: fix possible deadlock in rh control transfers
>From within the SCSI error handler memory allocations must not trigger IO. Handling errors in UAS and the storage driver may involve resetting a device. The thread doing the reset itself relies on VM magic. However, that is insufficient, as resetting a device involves resuming it. Resumption as well as resetting involves conrol transfers to the parent of the device to be reset. That may be a root hub. Hence usbcore must heed the flags passed to usb_submit_urb() processing control transfers to root hubs.
Leer descripción completaMostrar menos
The problem exist since the storage driver has been merged.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/549672a3fb6b36ea408238f89ecf9f41d2da6225
- https://git.kernel.org/stable/c/8461eda5af77c44d216cec66455bd5b01ee35c9a
- https://git.kernel.org/stable/c/8f82fc3d72e5feb7a1efae94b51b431c5bf41c86
- https://git.kernel.org/stable/c/936b08d87c667031725bcc753007e7c1182548c6
- https://git.kernel.org/stable/c/d0291fb4d91982d9f6a680bf759ff0555d351ecb
- https://git.kernel.org/stable/c/d5559f43d76b398392b26a15cbc16d731969cd1c
- https://git.kernel.org/stable/c/fff917c85d37a294397c5440a795591ca9d6b602
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97483",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "8461eda5af77c44d216cec66455bd5b01ee35c9a",
"versionType": "git"
},
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "8f82fc3d72e5feb7a1efae94b51b431c5bf41c86",
"versionType": "git"
},
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "936b08d87c667031725bcc753007e7c1182548c6",
"versionType": "git"
},
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "d0291fb4d91982d9f6a680bf759ff0555d351ecb",
"versionType": "git"
},
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "fff917c85d37a294397c5440a795591ca9d6b602",
"versionType": "git"
},
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "549672a3fb6b36ea408238f89ecf9f41d2da6225",
"versionType": "git"
},
{
"status": "affected",
"version": "e57e780b346a7277fdd3bde765d9d8728b99bfa1",
"lessThan": "d5559f43d76b398392b26a15cbc16d731969cd1c",
"versionType": "git"
}
],
"programFiles": [
"drivers/usb/core/hcd.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/usb/core/hcd.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:25.820",
"references": [
{
"url": "https://git.kernel.org/stable/c/549672a3fb6b36ea408238f89ecf9f41d2da6225",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8461eda5af77c44d216cec66455bd5b01ee35c9a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8f82fc3d72e5feb7a1efae94b51b431c5bf41c86",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/936b08d87c667031725bcc753007e7c1182548c6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d0291fb4d91982d9f6a680bf759ff0555d351ecb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d5559f43d76b398392b26a15cbc16d731969cd1c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fff917c85d37a294397c5440a795591ca9d6b602",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: hcd: fix possible deadlock in rh control transfers\n\n>From within the SCSI error handler memory allocations must not\ntrigger IO. Handling errors in UAS and the storage driver may\ninvolve resetting a device. The thread doing the reset itself\nrelies on VM magic. However, that is insufficient, as resetting\na device involves resuming it. Resumption as well as resetting\ninvolves conrol transfers to the parent of the device to be reset.\nThat may be a root hub. Hence usbcore must heed the flags passed\nto usb_submit_urb() processing control transfers to root hubs.\n\nThe problem exist since the storage driver has been merged."
}
],
"lastModified": "2026-10-03T11:17:58.227",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}