CVE-2026-10668

Source
https://cve.org/CVERecord?id=CVE-2026-10668
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10668.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10668
Aliases
  • GHSA-rm28-x84j-4qrx
Published
2026-07-12T16:16:51.243Z
Modified
2026-07-22T03:15:30.284700Z
Severity
  • 2.4 (Low) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
Details

The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udcnumaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numakerhsusbdeptrigger). Because the HSUSBD hardware cannot disarm a control Data IN already armed for a previous transfer, a USB host that cancels an in-flight control transfer (timeout) and then issues a new SETUP packet can drive the driver out of sync: stale data may be transmitted in the new transfer and the control endpoint can become permanently stuck NAK'ing every subsequent control transfer.

A malicious or buggy host (physical/adjacent attacker driving the bus) can repeatedly cancel-and-re-SETUP to wedge the device's USB control endpoint, denying service to the device's USB function (the device stops enumerating/responding on the control pipe) until a USB reset or re-plug. The flaw is an availability-only denial of service; the FIFO copy loops (bounded by netbuf length and the hardware BUFFULL flag) and the netbuf lifecycle are independent of the arming desync, so there is no out-of-bounds access, use-after-free, or information leak.

The fix monitors the IN-token and new-SETUP events (kevent) and only arms control Data IN when an IN token is present and no new SETUP has arrived, cancelling the current transfer on a new SETUP. Affects boards using the Nuvoton NuMaker HSUSBD controller (CONFIGUDCNUMAKER with DTHASNUVOTONNUMAKERHSUSBDENABLED); shipped in v4.4.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10668.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.4.0"
                },
                {
                    "fixed": "4.5.0"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-400"
    ],
    "cna_assigner": "zephyr"
}
References

Affected packages

Git / github.com/zephyrproject-rtos/zephyr

Affected ranges

Type
GIT
Repo
https://github.com/zephyrproject-rtos/zephyr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.1.0-rc1
v1.10.0
v1.10.0-rc1
v1.10.0-rc2
v1.10.0-rc3
v1.11.0
v1.11.0-rc1
v1.11.0-rc2
v1.11.0-rc3
v1.12.0
v1.12.0-rc1
v1.12.0-rc2
v1.12.0-rc3
v1.13.0
v1.13.0-rc1
v1.13.0-rc2
v1.13.0-rc3
v1.14.0
v1.14.0-rc1
v1.14.0-rc2
v1.14.0-rc3
v1.2.0
v1.2.0-rc1
v1.2.0-rc2
v1.3.0
v1.3.0-rc1
v1.3.0-rc2
v1.4.0
v1.4.0-rc1
v1.4.0-rc2
v1.4.0-rc3
v1.5.0
v1.5.0-rc0
v1.5.0-rc1
v1.5.0-rc2
v1.5.0-rc3
v1.5.0-rc4
v1.6.99
v1.7.99
v1.8.99
v1.9.0
v1.9.0-rc1
v1.9.0-rc2
v1.9.0-rc3
v1.9.0-rc4
v2.*
v2.0.0
v2.0.0-rc1
v2.0.0-rc2
v2.0.0-rc3
v2.1.0
v2.1.0-rc1
v2.1.0-rc2
v2.1.0-rc3
v2.2.0
v2.2.0-rc1
v2.2.0-rc2
v2.2.0-rc3
v2.3.0
v2.3.0-rc1
v2.3.0-rc2
v2.4.0
v2.4.0-rc1
v2.4.0-rc2
v2.4.0-rc3
v2.5.0
v2.5.0-rc1
v2.5.0-rc2
v2.5.0-rc3
v2.5.0-rc4
v2.6.0
v2.6.0-rc1
v2.6.0-rc2
v2.6.0-rc3
v2.7.0-rc1
v2.7.0-rc2
v2.7.0-rc3
v2.7.99
v3.*
v3.0.0
v3.0.0-rc1
v3.0.0-rc2
v3.0.0-rc3
v3.1.0
v3.1.0-rc1
v3.1.0-rc2
v3.1.0-rc3
v3.2.0
v3.2.0-rc1
v3.2.0-rc2
v3.2.0-rc3
v3.3.0
v3.3.0-rc1
v3.3.0-rc2
v3.3.0-rc3
v3.4.0
v3.4.0-rc1
v3.4.0-rc2
v3.4.0-rc3
v3.5.0
v3.5.0-rc1
v3.5.0-rc2
v3.5.0-rc3
v3.6.0
v3.6.0-rc1
v3.6.0-rc2
v3.6.0-rc3
v3.7.0
v3.7.0-rc1
v3.7.0-rc2
v3.7.0-rc3
v4.*
v4.0.0
v4.0.0-rc1
v4.0.0-rc2
v4.0.0-rc3
v4.1.0
v4.1.0-rc1
v4.1.0-rc2
v4.1.0-rc3
v4.2.0
v4.2.0-rc1
v4.2.0-rc2
v4.2.0-rc3
v4.3.0
v4.3.0-rc1
v4.3.0-rc2
v4.3.0-rc3
v4.4.0
v4.4.0-rc1
v4.4.0-rc2
v4.4.0-rc3
zephyr-v1.*
zephyr-v1.0.0
zephyr-v1.1.0
zephyr-v1.10.0
zephyr-v1.11.0
zephyr-v1.12.0
zephyr-v1.13.0
zephyr-v1.14.0
zephyr-v1.2.0
zephyr-v1.3.0
zephyr-v1.4.0
zephyr-v1.5.0
zephyr-v1.9.0
zephyr-v2.*
zephyr-v2.0.0
zephyr-v2.1.0
zephyr-v2.2.0
zephyr-v2.3.0
zephyr-v2.4.0
zephyr-v2.5.0
zephyr-v2.6.0
zephyr-v3.*
zephyr-v3.0.0
zephyr-v3.1.0
zephyr-v3.2.0
zephyr-v3.3.0
zephyr-v3.4.0
zephyr-v3.5.0

Database specific

vanir_signatures
[
    {
        "id": "CVE-2026-10668-01649bdf",
        "target": {
            "function": "numaker_usbd_setup_th",
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "294802644622432222452728181771543973167",
            "length": 417.0
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-10668-18dc4cc9",
        "target": {
            "function": "numaker_usbd_ep_th",
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "199899498820452951872873387320316611133",
            "length": 881.0
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-10668-35e18c17",
        "target": {
            "function": "numaker_hsusbd_cep_th",
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "212239203639149397585444336114230354849",
            "length": 988.0
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-10668-5aadf54b",
        "target": {
            "function": "numaker_usbd_msg_handle_setup",
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "200302612166562255512535830461200523904",
            "length": 1059.0
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-10668-b71aa87a",
        "target": {
            "function": "numaker_hsusbd_ep_trigger",
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "259217130851666443345745807267609963692",
            "length": 1247.0
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-10668-c961525b",
        "target": {
            "function": "udc_numaker_driver_preinit",
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "209744177636148665427396135275240675048",
            "length": 1955.0
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-10668-cecf480b",
        "target": {
            "file": "drivers/usb/udc/udc_numaker.c"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "241389319298828758155412359237575490051",
                "267055904774983317349638728921346387007",
                "40138118548230778008255266612941667642",
                "275046065276559897256636072759879234282",
                "32530242017450250541540051939140552967",
                "255380828010655616339518745637221977379",
                "100492035784340582716280462175624235590",
                "114285645307682133736964390271327749067",
                "109317845498026655607785193763121894604",
                "104988587042474614407231295697768313182",
                "225871503410594470815271421288829065707",
                "11669908138967421139441558434838288220",
                "328974649846732901683815576787432944827",
                "307577814714316669172416844609646604764",
                "338215714557520052180863809928365858225",
                "226925310355881346695537275873931970122",
                "164478775703085564434164384213117022061",
                "138263951981620687572486744864866758439",
                "175697311187174933202758335604804890097",
                "93237164439815077592996162089381459882",
                "71392853754803693621778314366652141811",
                "64304858125680409711860857753408069677",
                "187893672326624475372276793853607560312",
                "125901265339356648589673505474386623907",
                "6491507777104203554669675076412710217",
                "185167210619691597433800290998027245749",
                "173925807139309266035499105364069310157",
                "276202176694071034195555892590857491727",
                "176184562291609012968977574243477787223",
                "207865259613439440994404301686130648875",
                "145913377304301723931421822172469869901",
                "189457131755699308990406145829866357216",
                "115815126631472291737657172055085405327",
                "258879464636268114514269906129079757646",
                "236782500404038691611201929168572570803",
                "169518978909707772120578658196004662577",
                "338215714557520052180863809928365858225",
                "38374748597581438494344525832808826267",
                "239961554600311872959603801992881262200",
                "8652640204482289202764827715566003162",
                "284030959744367045918304269475110674105",
                "81436964055058554113419113157641829042",
                "266037353660085666874869413416003724426",
                "172225370413054222648542128688239257973",
                "185705523847884662306044097758801483813",
                "329735100072484430486884419840467291800",
                "85751920025150946971692036704924096403",
                "272977260060252353713746571484769882557",
                "64400482636567351965778678002229580463",
                "156758402341057987987580195257074515486",
                "40176666044894879608797774476589546686",
                "273643278986455083148215799693680925472",
                "246859851977276712200208529344209379762"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10668.json"
vanir_signatures_modified
"2026-07-22T03:15:30Z"