The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udcnumaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numakerhsusbdeptrigger). Because the HSUSBD hardware cannot disarm a control Data IN already armed for a previous transfer, a USB host that cancels an in-flight control transfer (timeout) and then issues a new SETUP packet can drive the driver out of sync: stale data may be transmitted in the new transfer and the control endpoint can become permanently stuck NAK'ing every subsequent control transfer.
A malicious or buggy host (physical/adjacent attacker driving the bus) can repeatedly cancel-and-re-SETUP to wedge the device's USB control endpoint, denying service to the device's USB function (the device stops enumerating/responding on the control pipe) until a USB reset or re-plug. The flaw is an availability-only denial of service; the FIFO copy loops (bounded by netbuf length and the hardware BUFFULL flag) and the netbuf lifecycle are independent of the arming desync, so there is no out-of-bounds access, use-after-free, or information leak.
The fix monitors the IN-token and new-SETUP events (kevent) and only arms control Data IN when an IN token is present and no new SETUP has arrived, cancelling the current transfer on a new SETUP. Affects boards using the Nuvoton NuMaker HSUSBD controller (CONFIGUDCNUMAKER with DTHASNUVOTONNUMAKERHSUSBDENABLED); shipped in v4.4.0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10668.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "4.4.0"
},
{
"fixed": "4.5.0"
}
]
}
],
"cwe_ids": [
"CWE-400"
],
"cna_assigner": "zephyr"
}[
{
"id": "CVE-2026-10668-01649bdf",
"target": {
"function": "numaker_usbd_setup_th",
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"function_hash": "294802644622432222452728181771543973167",
"length": 417.0
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Function"
},
{
"id": "CVE-2026-10668-18dc4cc9",
"target": {
"function": "numaker_usbd_ep_th",
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"function_hash": "199899498820452951872873387320316611133",
"length": 881.0
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Function"
},
{
"id": "CVE-2026-10668-35e18c17",
"target": {
"function": "numaker_hsusbd_cep_th",
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"function_hash": "212239203639149397585444336114230354849",
"length": 988.0
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Function"
},
{
"id": "CVE-2026-10668-5aadf54b",
"target": {
"function": "numaker_usbd_msg_handle_setup",
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"function_hash": "200302612166562255512535830461200523904",
"length": 1059.0
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Function"
},
{
"id": "CVE-2026-10668-b71aa87a",
"target": {
"function": "numaker_hsusbd_ep_trigger",
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"function_hash": "259217130851666443345745807267609963692",
"length": 1247.0
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Function"
},
{
"id": "CVE-2026-10668-c961525b",
"target": {
"function": "udc_numaker_driver_preinit",
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"function_hash": "209744177636148665427396135275240675048",
"length": 1955.0
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Function"
},
{
"id": "CVE-2026-10668-cecf480b",
"target": {
"file": "drivers/usb/udc/udc_numaker.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"241389319298828758155412359237575490051",
"267055904774983317349638728921346387007",
"40138118548230778008255266612941667642",
"275046065276559897256636072759879234282",
"32530242017450250541540051939140552967",
"255380828010655616339518745637221977379",
"100492035784340582716280462175624235590",
"114285645307682133736964390271327749067",
"109317845498026655607785193763121894604",
"104988587042474614407231295697768313182",
"225871503410594470815271421288829065707",
"11669908138967421139441558434838288220",
"328974649846732901683815576787432944827",
"307577814714316669172416844609646604764",
"338215714557520052180863809928365858225",
"226925310355881346695537275873931970122",
"164478775703085564434164384213117022061",
"138263951981620687572486744864866758439",
"175697311187174933202758335604804890097",
"93237164439815077592996162089381459882",
"71392853754803693621778314366652141811",
"64304858125680409711860857753408069677",
"187893672326624475372276793853607560312",
"125901265339356648589673505474386623907",
"6491507777104203554669675076412710217",
"185167210619691597433800290998027245749",
"173925807139309266035499105364069310157",
"276202176694071034195555892590857491727",
"176184562291609012968977574243477787223",
"207865259613439440994404301686130648875",
"145913377304301723931421822172469869901",
"189457131755699308990406145829866357216",
"115815126631472291737657172055085405327",
"258879464636268114514269906129079757646",
"236782500404038691611201929168572570803",
"169518978909707772120578658196004662577",
"338215714557520052180863809928365858225",
"38374748597581438494344525832808826267",
"239961554600311872959603801992881262200",
"8652640204482289202764827715566003162",
"284030959744367045918304269475110674105",
"81436964055058554113419113157641829042",
"266037353660085666874869413416003724426",
"172225370413054222648542128688239257973",
"185705523847884662306044097758801483813",
"329735100072484430486884419840467291800",
"85751920025150946971692036704924096403",
"272977260060252353713746571484769882557",
"64400482636567351965778678002229580463",
"156758402341057987987580195257074515486",
"40176666044894879608797774476589546686",
"273643278986455083148215799693680925472",
"246859851977276712200208529344209379762"
]
},
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10668.json"
"2026-07-22T03:15:30Z"