CVE-2026-64331
CVE CVE-2026-64331EUVD EUVD-2026-48875Published 2026-07-25T08:49:58.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: fix NULL deref in vep_dequeue() vep_alloc_request() wasn't initializing vrequest->udc, so cancellations on the FunctionFS AIO path were arriving in vep_dequeue without a valid UDC reference. Since vrequest->udc is never actually properly used anywhere, we opt to remove it, and update vep_dequeue to obtain a reference to the udc with ep_to_vudc(), consistent with the other vep_ ops. AFAICT this bug has existed for ~10 years. Seems that nobody has really stressed the FunctionFS AIO path on usbip's vudc. I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints via AIO. Before the fix, running `usbip attach` from the host would cause the guest to oops with the following backtrace: Call trace: vep_dequeue+0x1c/0xe4 (P) usb_ep_dequeue+0x14/0x20 ffs_aio_cancel+0x24/0x34 __arm64_sys_io_cancel+0xb0/0x124 do_el0_svc+0x68/0x100 el0_svc+0x18/0x5c el0t_64_sync_handler+0x98/0xdc el0t_64_sync+0x154/0x158
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux b6a0ca11186759ad7045d68a5447b1e89f658384 <347b59e9f96719d89b6ef555d02a18ada1a5846f; b6a0ca11186759ad7045d68a5447b1e89f658384 <c5371e0b91b24159a3ebaa61e70b0980bcf03c0a; patch: 0; 4.7; b6a0ca11186759ad7045d68a5447b1e89f658384 <d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97; b6a0ca11186759ad7045d68a5447b1e89f658384 <0443e4416aa1ee97748d1ed904eaf3352c60045e; patch: 6.18.39; patch: 6.1.178; patch: 6.6.145; patch: 5.10.261; b6a0ca11186759ad7045d68a5447b1e89f658384 <0025276175fbbe0dcbf3f84d090b0adee769e9d9; patch: 7.1.4; patch: 6.12.96; b6a0ca11186759ad7045d68a5447b1e89f658384 <9858c91d9ee6a13c45311569039413729fc9b757; patch: 7.2-rc3; b6a0ca11186759ad7045d68a5447b1e89f658384 <1226293ec9bed3d4cc5b05eeeb811d315ca51652; patch: 5.15.212; b6a0ca11186759ad7045d68a5447b1e89f658384 <3750f75f29f99c0223601e2ee73ad084adec47bd
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.