usb: mtu3: unmap request DMA on queue failure

Summary

CVECVE-2026-64337
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:15 UTC
Updated2026-07-25 10:17:15 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: usb: mtu3: unmap request DMA on queue failure mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails. Normal completion and dequeue paths unmap requests from mtu3_req_complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.

Risk And Classification

EPSS: 0.002110000 probability, percentile 0.114710000 (date 2026-07-28)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 3cee30f1138281a1d247bb053a1ad4f7c5b04e98 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 f3c4026524d3660c73ef2838b99776d37631e039 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 e8f739a3860d043dcc135371637e82f53132efe5 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 4183874b7925f4a98b400cf857bea26ee87da236 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 00c3fef4c2dc2c7cbd8281f8fda09d1913420f09 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 835b0596d4c9bdef93f842d8f826978fb4956b74 git Not specified
CNA Linux Linux affected df2069acb00569a6299d6e11aa1865eeba463848 0bddda5a11665c210339de76d27ebbd1a2e0b43c git Not specified
CNA Linux Linux affected 4.10 Not specified
CNA Linux Linux unaffected 4.10 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/f3c4026524d3660c73ef2838b99776d37631e039 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report