usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
Summary
| CVE | CVE-2026-64327 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-25 10:17:14 UTC |
| Updated | 2026-08-17 05:17:33 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks When parsing endpoint descriptors, ffs_data_got_descs() generates the eps_addrmap which contains the endpoint direction. However, epfile->in was previously only populated in ffs_func_eps_enable() which executes upon USB host connection. As a result, early userspace ioctls like FUNCTIONFS_DMABUF_ATTACH that run before the host connects would see epfile->in as 0, leading to incorrect DMA directions. By moving the initialization to ffs_epfiles_create(), epfile->in is accurate before userspace opens the endpoint files. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.101990000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 7b07a2a7ca02a20124b552be96c5a56910795488 82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b git | Not specified |
| CNA | Linux | Linux | affected 7b07a2a7ca02a20124b552be96c5a56910795488 9e04055ab5fc0470a0031ee6934739f9aa8f34a5 git | Not specified |
| CNA | Linux | Linux | affected 7b07a2a7ca02a20124b552be96c5a56910795488 f99f32ea9aa976afcbec20647ed33b50a52002c1 git | Not specified |
| CNA | Linux | Linux | affected 7b07a2a7ca02a20124b552be96c5a56910795488 82cfd4739011bdc7e87b5d585703427e89ddfaa5 git | Not specified |
| CNA | Linux | Linux | affected 6.9 | Not specified |
| CNA | Linux | Linux | unaffected 6.9 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.96 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.39 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.4 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/f99f32ea9aa976afcbec20647ed33b50a52002c1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/82cfd4739011bdc7e87b5d585703427e89ddfaa5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9e04055ab5fc0470a0031ee6934739f9aa8f34a5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.