{"api_version":"1","generated_at":"2026-09-17T14:27:19+00:00","cve":"CVE-2026-90015","urls":{"html":"https://cve.report/CVE-2026-90015","api":"https://cve.report/api/cve/CVE-2026-90015.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90015","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90015"},"summary":{"title":"xhci: fix lost bounce buffers on TDs spanning several ring segments","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: fix lost bounce buffers on TDs spanning several ring segments\n\nWhen a TD reaches a link TRB with data that is not aligned to the\nendpoint's wMaxPacketSize, xhci_align_td() stages the unalignable tail\nthrough the bounce buffer of the ring segment holding that link TRB.\nxhci_unmap_td_bounce_buffer() later unmaps it and, for IN transfers,\ncopies the data back into the URB's buffer.\n\nThe enqueue path records the segment that was bounced in td->bounce_seg,\nunder the assumption that a TD never spans more than two ring segments.\nThat assumption does not hold: a TD large enough to span three or more\nsegments crosses several link TRBs and can be bounced at each of them.\nOnly the last one survives in td->bounce_seg, so every earlier bounce\nbuffer is neither copied back nor DMA unmapped.\n\nThe URB still completes with actual_length equal to the requested length\nand no error, so the transfer looks successful while a wMaxPacketSize\nsized hole in the destination buffer silently keeps its previous\ncontents. It also leaks a DMA mapping per dropped bounce.\n\nAny sufficiently large and fragmented bulk transfer can hit this. It was\nfound with a USB mass storage device behind xHCI backing a dm-verity\ntarget with 512 byte hash blocks, where the stale data is detected rather\nthan silently consumed. The device enumerates as SuperSpeed, so\nwMaxPacketSize is 1024, while dm-bufio issues one 512 byte bio per hash\nblock. verity_prefetch_io() makes the block layer merge hundreds of them\ninto a single request of up to 512 scatterlist entries of 512 bytes each.\nAt 256 TRBs per ring segment such a TD spans three segments, and every\nsegment boundary falls on an odd multiple of 512, i.e. unaligned to\nwMaxPacketSize. dm-bufio then caches a hash block holding stale data and\ndm-verity declares the metadata block corrupted:\n\n  device-mapper: verity: 8:2: metadata block 10850 is corrupted\n\nA reproducer running this under qemu is available at\nhttps://github.com/baloo/xhci-verity\n\nThe bounce state (bounce_buf, bounce_dma, bounce_len, bounce_offs)\nalready lives on the ring segment, so there is nothing extra to track.\nKeep recording the last bounced segment in td->bounce_seg and, on\ncompletion, walk the segments from td->start_seg up to it, unmapping\nevery segment that still has a pending bounce.\n\nStopping at td->bounce_seg rather than td->end_seg matters: a bounce\nimplies the TD continues past that segment's link TRB, so bounce_seg is\nalways strictly before end_seg, and a later TD may already have started\nin end_seg and been bounced there. Walking that far would copy a foreign\nbounce buffer into this URB and unmap it twice. It also keeps the walk\ncorrect if a TD ever wraps the whole ring so that end_seg == start_seg.\n\n[mn: Add ring->num_segs check to prevent unlikely infinite for loop.]","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:17:14","updated_at":"2026-09-16 11:17:14"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/efaab8938fb92979be6df359f7d1a43fb7e4717d","name":"https://git.kernel.org/stable/c/efaab8938fb92979be6df359f7d1a43fb7e4717d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c8124b28f12dbdd126118e63d0ebf8093a01fb81","name":"https://git.kernel.org/stable/c/c8124b28f12dbdd126118e63d0ebf8093a01fb81","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3c9a2b5a4f1183696f02ac280ced1d34afb409b1","name":"https://git.kernel.org/stable/c/3c9a2b5a4f1183696f02ac280ced1d34afb409b1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7236bbd2cb7d9fc0eda896bbd34790341e2a4377","name":"https://git.kernel.org/stable/c/7236bbd2cb7d9fc0eda896bbd34790341e2a4377","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a1629dfb011446d02905778f6df19f14c5f4f3b3","name":"https://git.kernel.org/stable/c/a1629dfb011446d02905778f6df19f14c5f4f3b3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e04d5304a248e5d2a7f4faa87541644bdd320cfb","name":"https://git.kernel.org/stable/c/e04d5304a248e5d2a7f4faa87541644bdd320cfb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/43239fc6dfb62c50ae1b9c0e82bac0f8cd2e285c","name":"https://git.kernel.org/stable/c/43239fc6dfb62c50ae1b9c0e82bac0f8cd2e285c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ff44dfb03a293bf30e31f98772a1dd316a6071d1","name":"https://git.kernel.org/stable/c/ff44dfb03a293bf30e31f98772a1dd316a6071d1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90015","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90015","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed c8124b28f12dbdd126118e63d0ebf8093a01fb81 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed e04d5304a248e5d2a7f4faa87541644bdd320cfb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed a1629dfb011446d02905778f6df19f14c5f4f3b3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed 43239fc6dfb62c50ae1b9c0e82bac0f8cd2e285c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed 3c9a2b5a4f1183696f02ac280ced1d34afb409b1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed efaab8938fb92979be6df359f7d1a43fb7e4717d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed 7236bbd2cb7d9fc0eda896bbd34790341e2a4377 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f9c589e142d04b8a19eb382162f804d17102b5ed ff44dfb03a293bf30e31f98772a1dd316a6071d1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.270 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/usb/host/xhci-ring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c8124b28f12dbdd126118e63d0ebf8093a01fb81","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"e04d5304a248e5d2a7f4faa87541644bdd320cfb","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"a1629dfb011446d02905778f6df19f14c5f4f3b3","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"43239fc6dfb62c50ae1b9c0e82bac0f8cd2e285c","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"3c9a2b5a4f1183696f02ac280ced1d34afb409b1","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"efaab8938fb92979be6df359f7d1a43fb7e4717d","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"7236bbd2cb7d9fc0eda896bbd34790341e2a4377","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"},{"lessThan":"ff44dfb03a293bf30e31f98772a1dd316a6071d1","status":"affected","version":"f9c589e142d04b8a19eb382162f804d17102b5ed","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/usb/host/xhci-ring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.8"},{"lessThan":"4.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.270","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.270","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc2","versionStartIncluding":"4.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: fix lost bounce buffers on TDs spanning several ring segments\n\nWhen a TD reaches a link TRB with data that is not aligned to the\nendpoint's wMaxPacketSize, xhci_align_td() stages the unalignable tail\nthrough the bounce buffer of the ring segment holding that link TRB.\nxhci_unmap_td_bounce_buffer() later unmaps it and, for IN transfers,\ncopies the data back into the URB's buffer.\n\nThe enqueue path records the segment that was bounced in td->bounce_seg,\nunder the assumption that a TD never spans more than two ring segments.\nThat assumption does not hold: a TD large enough to span three or more\nsegments crosses several link TRBs and can be bounced at each of them.\nOnly the last one survives in td->bounce_seg, so every earlier bounce\nbuffer is neither copied back nor DMA unmapped.\n\nThe URB still completes with actual_length equal to the requested length\nand no error, so the transfer looks successful while a wMaxPacketSize\nsized hole in the destination buffer silently keeps its previous\ncontents. It also leaks a DMA mapping per dropped bounce.\n\nAny sufficiently large and fragmented bulk transfer can hit this. It was\nfound with a USB mass storage device behind xHCI backing a dm-verity\ntarget with 512 byte hash blocks, where the stale data is detected rather\nthan silently consumed. The device enumerates as SuperSpeed, so\nwMaxPacketSize is 1024, while dm-bufio issues one 512 byte bio per hash\nblock. verity_prefetch_io() makes the block layer merge hundreds of them\ninto a single request of up to 512 scatterlist entries of 512 bytes each.\nAt 256 TRBs per ring segment such a TD spans three segments, and every\nsegment boundary falls on an odd multiple of 512, i.e. unaligned to\nwMaxPacketSize. dm-bufio then caches a hash block holding stale data and\ndm-verity declares the metadata block corrupted:\n\n  device-mapper: verity: 8:2: metadata block 10850 is corrupted\n\nA reproducer running this under qemu is available at\nhttps://github.com/baloo/xhci-verity\n\nThe bounce state (bounce_buf, bounce_dma, bounce_len, bounce_offs)\nalready lives on the ring segment, so there is nothing extra to track.\nKeep recording the last bounced segment in td->bounce_seg and, on\ncompletion, walk the segments from td->start_seg up to it, unmapping\nevery segment that still has a pending bounce.\n\nStopping at td->bounce_seg rather than td->end_seg matters: a bounce\nimplies the TD continues past that segment's link TRB, so bounce_seg is\nalways strictly before end_seg, and a later TD may already have started\nin end_seg and been bounced there. Walking that far would copy a foreign\nbounce buffer into this URB and unmap it twice. It also keeps the walk\ncorrect if a TD ever wraps the whole ring so that end_seg == start_seg.\n\n[mn: Add ring->num_segs check to prevent unlikely infinite for loop.]"}],"providerMetadata":{"dateUpdated":"2026-09-16T10:33:21.471Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c8124b28f12dbdd126118e63d0ebf8093a01fb81"},{"url":"https://git.kernel.org/stable/c/e04d5304a248e5d2a7f4faa87541644bdd320cfb"},{"url":"https://git.kernel.org/stable/c/a1629dfb011446d02905778f6df19f14c5f4f3b3"},{"url":"https://git.kernel.org/stable/c/43239fc6dfb62c50ae1b9c0e82bac0f8cd2e285c"},{"url":"https://git.kernel.org/stable/c/3c9a2b5a4f1183696f02ac280ced1d34afb409b1"},{"url":"https://git.kernel.org/stable/c/efaab8938fb92979be6df359f7d1a43fb7e4717d"},{"url":"https://git.kernel.org/stable/c/7236bbd2cb7d9fc0eda896bbd34790341e2a4377"},{"url":"https://git.kernel.org/stable/c/ff44dfb03a293bf30e31f98772a1dd316a6071d1"}],"title":"xhci: fix lost bounce buffers on TDs spanning several ring segments","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90015","datePublished":"2026-09-16T10:33:21.471Z","dateReserved":"2026-09-11T19:38:34.781Z","dateUpdated":"2026-09-16T10:33:21.471Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:17:14","lastModifiedDate":"2026-09-16 11:17:14","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90015","Ordinal":"1","Title":"xhci: fix lost bounce buffers on TDs spanning several ring segme","CVE":"CVE-2026-90015","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90015","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: fix lost bounce buffers on TDs spanning several ring segments\n\nWhen a TD reaches a link TRB with data that is not aligned to the\nendpoint's wMaxPacketSize, xhci_align_td() stages the unalignable tail\nthrough the bounce buffer of the ring segment holding that link TRB.\nxhci_unmap_td_bounce_buffer() later unmaps it and, for IN transfers,\ncopies the data back into the URB's buffer.\n\nThe enqueue path records the segment that was bounced in td->bounce_seg,\nunder the assumption that a TD never spans more than two ring segments.\nThat assumption does not hold: a TD large enough to span three or more\nsegments crosses several link TRBs and can be bounced at each of them.\nOnly the last one survives in td->bounce_seg, so every earlier bounce\nbuffer is neither copied back nor DMA unmapped.\n\nThe URB still completes with actual_length equal to the requested length\nand no error, so the transfer looks successful while a wMaxPacketSize\nsized hole in the destination buffer silently keeps its previous\ncontents. It also leaks a DMA mapping per dropped bounce.\n\nAny sufficiently large and fragmented bulk transfer can hit this. It was\nfound with a USB mass storage device behind xHCI backing a dm-verity\ntarget with 512 byte hash blocks, where the stale data is detected rather\nthan silently consumed. The device enumerates as SuperSpeed, so\nwMaxPacketSize is 1024, while dm-bufio issues one 512 byte bio per hash\nblock. verity_prefetch_io() makes the block layer merge hundreds of them\ninto a single request of up to 512 scatterlist entries of 512 bytes each.\nAt 256 TRBs per ring segment such a TD spans three segments, and every\nsegment boundary falls on an odd multiple of 512, i.e. unaligned to\nwMaxPacketSize. dm-bufio then caches a hash block holding stale data and\ndm-verity declares the metadata block corrupted:\n\n  device-mapper: verity: 8:2: metadata block 10850 is corrupted\n\nA reproducer running this under qemu is available at\nhttps://github.com/baloo/xhci-verity\n\nThe bounce state (bounce_buf, bounce_dma, bounce_len, bounce_offs)\nalready lives on the ring segment, so there is nothing extra to track.\nKeep recording the last bounced segment in td->bounce_seg and, on\ncompletion, walk the segments from td->start_seg up to it, unmapping\nevery segment that still has a pending bounce.\n\nStopping at td->bounce_seg rather than td->end_seg matters: a bounce\nimplies the TD continues past that segment's link TRB, so bounce_seg is\nalways strictly before end_seg, and a later TD may already have started\nin end_seg and been bounced there. Walking that far would copy a foreign\nbounce buffer into this URB and unmap it twice. It also keeps the walk\ncorrect if a TD ever wraps the whole ring so that end_seg == start_seg.\n\n[mn: Add ring->num_segs check to prevent unlikely infinite for loop.]","Type":"Description","Title":"xhci: fix lost bounce buffers on TDs spanning several ring segme"}]}}}