CVE-2026-64337 (GCVE-0-2026-64337)
Vulnerability from cvelistv5
Published
2026-07-25 08:50
Modified
2026-08-17 04:53
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: unmap request DMA on queue failure mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails. Normal completion and dequeue paths unmap requests from mtu3_req_complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.
Impacted products
Vendor Product Version
Linux Linux Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Version: df2069acb00569a6299d6e11aa1865eeba463848
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/usb/mtu3/mtu3_gadget.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "3cee30f1138281a1d247bb053a1ad4f7c5b04e98",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "f3c4026524d3660c73ef2838b99776d37631e039",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "e8f739a3860d043dcc135371637e82f53132efe5",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "4183874b7925f4a98b400cf857bea26ee87da236",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "00c3fef4c2dc2c7cbd8281f8fda09d1913420f09",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "835b0596d4c9bdef93f842d8f826978fb4956b74",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            },
            {
              "lessThan": "0bddda5a11665c210339de76d27ebbd1a2e0b43c",
              "status": "affected",
              "version": "df2069acb00569a6299d6e11aa1865eeba463848",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/usb/mtu3/mtu3_gadget.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.10"
            },
            {
              "lessThan": "4.10",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.261",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.212",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.178",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.96",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.39",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.4",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "4.10",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: mtu3: unmap request DMA on queue failure\n\nmtu3_gadget_queue() maps the request before checking whether\nthe QMU GPD ring can accept another transfer. the request is\nreturned with -EAGAIN before it is linked on the endpoint\nrequest list if mtu3_prepare_transfer() fails.\n\nNormal completion and dequeue paths unmap requests from\nmtu3_req_complete(), but this error path never reaches that\nhelper, so the DMA mapping is left active. Unmap the request\nbefore returning from the failed queue path."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T04:53:40.517Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98"
        },
        {
          "url": "https://git.kernel.org/stable/c/f3c4026524d3660c73ef2838b99776d37631e039"
        },
        {
          "url": "https://git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5"
        },
        {
          "url": "https://git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236"
        },
        {
          "url": "https://git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09"
        },
        {
          "url": "https://git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1"
        },
        {
          "url": "https://git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74"
        },
        {
          "url": "https://git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c"
        }
      ],
      "title": "usb: mtu3: unmap request DMA on queue failure",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64337",
    "datePublished": "2026-07-25T08:50:02.066Z",
    "dateReserved": "2026-07-19T15:36:31.781Z",
    "dateUpdated": "2026-08-17T04:53:40.517Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…