CVE-2026-64349

Summary

In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()

The dwc3_ulpi_setup() calls the register read and write calls with dwc3->regs when both these calls take the dwc3 structure directly.

Chnage these two calls to fix the following sparse warning, and possibly a nasty bug in the dwc3_ulpi_setup() code:

drivers/usb/dwc3/core.c:796:45: warning: incorrect type in argument 1 (different address spaces) drivers/usb/dwc3/core.c:796:45: expected struct dwc3 *dwc drivers/usb/dwc3/core.c:796:45: got void [noderef] __iomem *regs drivers/usb/dwc3/core.c:798:40: warning: incorrect type in argument 1 (different address spaces) drivers/usb/dwc3/core.c:798:40: expected struct dwc3 *dwc drivers/usb/dwc3/core.c:798:40: got void [noderef] __iomem *regs

Affected Software

VendorProductVersion RangeStatus
LinuxLinux476ee6389120e1900290b46081b3a12b54e05672 < 41a4e80d5af04855e68ac88f5e2cd07fa67287f8affected
LinuxLinux9accc68b1cf0a2b220f51d53641128bb32598070 < 4349e487a1149ff33b65d53427b8aca57f2e4578affected
LinuxLinux9accc68b1cf0a2b220f51d53641128bb32598070 < e0f844d9d74200d311c6438a0f04270834ba5365affected
LinuxLinux6.18.32 < 6.18.40affected
LinuxLinux7.0affected
LinuxLinux0 < 7.0unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc3 <= *unaffected

Weaknesses

References