CVE-2026-64337

Summary

In the Linux kernel, the following vulnerability has been resolved:

usb: mtu3: unmap request DMA on queue failure

mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails.

Normal completion and dequeue paths unmap requests from mtu3_req_complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < 3cee30f1138281a1d247bb053a1ad4f7c5b04e98affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < f3c4026524d3660c73ef2838b99776d37631e039affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < e8f739a3860d043dcc135371637e82f53132efe5affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < 4183874b7925f4a98b400cf857bea26ee87da236affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < 00c3fef4c2dc2c7cbd8281f8fda09d1913420f09affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < 8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < 835b0596d4c9bdef93f842d8f826978fb4956b74affected
LinuxLinuxdf2069acb00569a6299d6e11aa1865eeba463848 < 0bddda5a11665c210339de76d27ebbd1a2e0b43caffected
LinuxLinux4.10affected
LinuxLinux0 < 4.10unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.96 <= 6.12.*unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc3 <= *unaffected

Weaknesses

References