{"api_version":"1","generated_at":"2026-07-24T20:32:59+00:00","cve":"CVE-2026-64240","urls":{"html":"https://cve.report/CVE-2026-64240","api":"https://cve.report/api/cve/CVE-2026-64240.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64240","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64240"},"summary":{"title":"media: rc: igorplugusb: fix control request setup packet","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: igorplugusb: fix control request setup packet\n\nCommit eac69475b01f (\"media: rc: igorplugusb: heed coherency\nrules\") changed the control request storage from an embedded struct to\nan allocated pointer so it can obey DMA coherency rules.\n\nHowever, the driver still passes &ir->request to usb_fill_control_urb().\nThat points the URB setup packet at the pointer field itself rather than\nat the allocated struct usb_ctrlrequest.\n\nUSB core then interprets pointer bytes as the setup packet. This can\nproduce an invalid bRequestType and trigger the control direction warning\nreported by syzbot:\n\n  usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0\n\nPass ir->request itself as the setup packet.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-24 16:16:53","updated_at":"2026-07-24 16:16:53"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/e823e4294511989f5962e7ad85bf4d179ba74f52","name":"https://git.kernel.org/stable/c/e823e4294511989f5962e7ad85bf4d179ba74f52","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/060fca8e098387f949e4eedaf215d952e477ac12","name":"https://git.kernel.org/stable/c/060fca8e098387f949e4eedaf215d952e477ac12","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0d880d2db9856e94127ab09331363bef59f98005","name":"https://git.kernel.org/stable/c/0d880d2db9856e94127ab09331363bef59f98005","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/171022c7d594c133a45f92357a2a91475edabe20","name":"https://git.kernel.org/stable/c/171022c7d594c133a45f92357a2a91475edabe20","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f33b5a61673bd220fdaaf4202cf1013d6d66c943","name":"https://git.kernel.org/stable/c/f33b5a61673bd220fdaaf4202cf1013d6d66c943","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/aa22590a16e51455c6db802c774b31aadc604a9a","name":"https://git.kernel.org/stable/c/aa22590a16e51455c6db802c774b31aadc604a9a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5cc3f6db72f77d1a8f7f1cf4ac01803927ffdf15","name":"https://git.kernel.org/stable/c/5cc3f6db72f77d1a8f7f1cf4ac01803927ffdf15","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2243ad78ce64d344754260533ae7730c2174a34a","name":"https://git.kernel.org/stable/c/2243ad78ce64d344754260533ae7730c2174a34a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64240","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64240","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected bc04b8633b375af6ac8a8bb615258b80fe06cdaa e823e4294511989f5962e7ad85bf4d179ba74f52 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 81f0fb813e4bf28b3ca28dc218938a32eb48f740 2243ad78ce64d344754260533ae7730c2174a34a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0e84aa8fc23c7578f105e3a2160f9d0aa2bed79a aa22590a16e51455c6db802c774b31aadc604a9a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 18d6a7c9e4e63c57157e9a57dd9bf3cd38e4c45a 060fca8e098387f949e4eedaf215d952e477ac12 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0be8fcd9005e3d3b5a61fe34b070a9663adbb4dc 0d880d2db9856e94127ab09331363bef59f98005 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0adac0ee2c42027d80bac02ea9b576a88f8955d3 f33b5a61673bd220fdaaf4202cf1013d6d66c943 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a62ca67e3c72fb297dc7c86495ba8f7329d7f150 5cc3f6db72f77d1a8f7f1cf4ac01803927ffdf15 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eac69475b01fe1e861dfe3960b57fa95671c132e 171022c7d594c133a45f92357a2a91475edabe20 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.140 6.6.143 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.86 6.12.93 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.27 6.18.35 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0.4 7.0.12 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/media/rc/igorplugusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e823e4294511989f5962e7ad85bf4d179ba74f52","status":"affected","version":"bc04b8633b375af6ac8a8bb615258b80fe06cdaa","versionType":"git"},{"lessThan":"2243ad78ce64d344754260533ae7730c2174a34a","status":"affected","version":"81f0fb813e4bf28b3ca28dc218938a32eb48f740","versionType":"git"},{"lessThan":"aa22590a16e51455c6db802c774b31aadc604a9a","status":"affected","version":"0e84aa8fc23c7578f105e3a2160f9d0aa2bed79a","versionType":"git"},{"lessThan":"060fca8e098387f949e4eedaf215d952e477ac12","status":"affected","version":"18d6a7c9e4e63c57157e9a57dd9bf3cd38e4c45a","versionType":"git"},{"lessThan":"0d880d2db9856e94127ab09331363bef59f98005","status":"affected","version":"0be8fcd9005e3d3b5a61fe34b070a9663adbb4dc","versionType":"git"},{"lessThan":"f33b5a61673bd220fdaaf4202cf1013d6d66c943","status":"affected","version":"0adac0ee2c42027d80bac02ea9b576a88f8955d3","versionType":"git"},{"lessThan":"5cc3f6db72f77d1a8f7f1cf4ac01803927ffdf15","status":"affected","version":"a62ca67e3c72fb297dc7c86495ba8f7329d7f150","versionType":"git"},{"lessThan":"171022c7d594c133a45f92357a2a91475edabe20","status":"affected","version":"eac69475b01fe1e861dfe3960b57fa95671c132e","versionType":"git"}]},{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/media/rc/igorplugusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6.6.143","status":"affected","version":"6.6.140","versionType":"semver"},{"lessThan":"6.12.93","status":"affected","version":"6.12.86","versionType":"semver"},{"lessThan":"6.18.35","status":"affected","version":"6.18.27","versionType":"semver"},{"lessThan":"7.0.12","status":"affected","version":"7.0.4","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.143","versionStartIncluding":"6.6.140","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.93","versionStartIncluding":"6.12.86","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.35","versionStartIncluding":"6.18.27","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.12","versionStartIncluding":"7.0.4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: igorplugusb: fix control request setup packet\n\nCommit eac69475b01f (\"media: rc: igorplugusb: heed coherency\nrules\") changed the control request storage from an embedded struct to\nan allocated pointer so it can obey DMA coherency rules.\n\nHowever, the driver still passes &ir->request to usb_fill_control_urb().\nThat points the URB setup packet at the pointer field itself rather than\nat the allocated struct usb_ctrlrequest.\n\nUSB core then interprets pointer bytes as the setup packet. This can\nproduce an invalid bRequestType and trigger the control direction warning\nreported by syzbot:\n\n  usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0\n\nPass ir->request itself as the setup packet."}],"providerMetadata":{"dateUpdated":"2026-07-24T15:27:43.590Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e823e4294511989f5962e7ad85bf4d179ba74f52"},{"url":"https://git.kernel.org/stable/c/2243ad78ce64d344754260533ae7730c2174a34a"},{"url":"https://git.kernel.org/stable/c/aa22590a16e51455c6db802c774b31aadc604a9a"},{"url":"https://git.kernel.org/stable/c/060fca8e098387f949e4eedaf215d952e477ac12"},{"url":"https://git.kernel.org/stable/c/0d880d2db9856e94127ab09331363bef59f98005"},{"url":"https://git.kernel.org/stable/c/f33b5a61673bd220fdaaf4202cf1013d6d66c943"},{"url":"https://git.kernel.org/stable/c/5cc3f6db72f77d1a8f7f1cf4ac01803927ffdf15"},{"url":"https://git.kernel.org/stable/c/171022c7d594c133a45f92357a2a91475edabe20"}],"title":"media: rc: igorplugusb: fix control request setup packet","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64240","datePublished":"2026-07-24T15:27:43.590Z","dateReserved":"2026-07-19T15:36:31.772Z","dateUpdated":"2026-07-24T15:27:43.590Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-24 16:16:53","lastModifiedDate":"2026-07-24 16:16:53","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64240","Ordinal":"1","Title":"media: rc: igorplugusb: fix control request setup packet","CVE":"CVE-2026-64240","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64240","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: igorplugusb: fix control request setup packet\n\nCommit eac69475b01f (\"media: rc: igorplugusb: heed coherency\nrules\") changed the control request storage from an embedded struct to\nan allocated pointer so it can obey DMA coherency rules.\n\nHowever, the driver still passes &ir->request to usb_fill_control_urb().\nThat points the URB setup packet at the pointer field itself rather than\nat the allocated struct usb_ctrlrequest.\n\nUSB core then interprets pointer bytes as the setup packet. This can\nproduce an invalid bRequestType and trigger the control direction warning\nreported by syzbot:\n\n  usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0\n\nPass ir->request itself as the setup packet.","Type":"Description","Title":"media: rc: igorplugusb: fix control request setup packet"}]}}}