CVE-2026-64331 Details
Description
In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: fix NULL deref in vep_dequeue() vep_alloc_request() wasn't initializing vrequest->udc, so cancellations on the FunctionFS AIO path were arriving in vep_dequeue without a valid UDC reference. Since vrequest->udc is never actually properly used anywhere, we opt to remove it, and update vep_dequeue to obtain a reference to the udc with ep_to_vudc(), consistent with the other vep_ ops. AFAICT this bug has existed for ~10 years. Seems that nobody has really stressed the FunctionFS AIO path on usbip's vudc. I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints via AIO. Before the fix, running `usbip attach` from the host would cause the guest to oops with the following backtrace: Call trace: vep_dequeue+0x1c/0xe4 (P) usb_ep_dequeue+0x14/0x20 ffs_aio_cancel+0x24/0x34 __arm64_sys_io_cancel+0xb0/0x124 do_el0_svc+0x68/0x100 el0_svc+0x18/0x5c el0t_64_sync_handler+0x98/0xdc el0t_64_sync+0x154/0x158
A vulnerability in the Linux kernel's USBIP virtual USB device controller (VUDC) has been addressed. The issue arose because the function 'vep_alloc_request()' did not properly initialize a request's UDC reference. This oversight led to cancellations on the FunctionFS asynchronous I/O path arriving at 'vep_dequeue()' without a valid UDC reference. Although this bug has existed for approximately ten years, it went unnoticed until now. The vulnerability could cause a NULL pointer dereference, leading to a crash. The issue was discovered while testing USBIP with QEMU, where attaching a USB device from the host to a guest would result in a kernel oops error.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0025276175fbbe0dcbf3f84d090b0adee769e9d9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/0443e4416aa1ee97748d1ed904eaf3352c60045e | kernel.org | Patch |
| https://git.kernel.org/stable/c/1226293ec9bed3d4cc5b05eeeb811d315ca51652 | kernel.org | Patch |
| https://git.kernel.org/stable/c/347b59e9f96719d89b6ef555d02a18ada1a5846f | kernel.org | Patch |
| https://git.kernel.org/stable/c/3750f75f29f99c0223601e2ee73ad084adec47bd | kernel.org | Patch |
| https://git.kernel.org/stable/c/9858c91d9ee6a13c45311569039413729fc9b757 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c5371e0b91b24159a3ebaa61e70b0980bcf03c0a | kernel.org | Patch |
| https://git.kernel.org/stable/c/d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.7, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 7.2 rc1 7.2 rc2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |