CVE-2026-63927

Source
https://cve.org/CVERecord?id=CVE-2026-63927
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63927.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63927
Downstream
Published
2026-07-19T14:55:27.864Z
Modified
2026-07-21T03:47:39.304719475Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
usb: dwc2: Fix use after free in debug code
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: dwc2: Fix use after free in debug code

We're not allowed to dereference "urb" after calling usbhcdgiveback_urb() so save the urb->status ahead of time.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63927.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7359d482eb4d3967cc8be354405ae6be6eaf732c
Fixed
d5fc183ed614aeba6779cc992325be560f9a4451
Fixed
63b0dafa676aad4d0c3f01a61ad8e2990907660c
Fixed
9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913
Fixed
0584af4fe40fa5e254a05d69ce658746de641708
Fixed
a15eeeceb94cbc04edef395e4d777ff554bdc27d
Fixed
84ea928ed584756e59c6ac09736f12d1db95ded0
Fixed
6d0b79d1d1118145e48a68192b6d733e39387053
Fixed
9ea06a3fbf9f16e0d98c52cb3b99642be15ec281

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63927.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63927.json"