CVE-2026-64331

Source
https://cve.org/CVERecord?id=CVE-2026-64331
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64331.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64331
Downstream
Published
2026-07-25T08:49:58.370Z
Modified
2026-07-27T04:03:21.484276156Z
Summary
usbip: vudc: fix NULL deref in vep_dequeue()
Details

In the Linux kernel, the following vulnerability has been resolved:

usbip: vudc: fix NULL deref in vep_dequeue()

vepallocrequest() wasn't initializing vrequest->udc, so cancellations on the FunctionFS AIO path were arriving in vep_dequeue without a valid UDC reference.

Since vrequest->udc is never actually properly used anywhere, we opt to remove it, and update vepdequeue to obtain a reference to the udc with eptovudc(), consistent with the other vep ops.

AFAICT this bug has existed for ~10 years. Seems that nobody has really stressed the FunctionFS AIO path on usbip's vudc.

I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints via AIO. Before the fix, running usbip attach from the host would cause the guest to oops with the following backtrace:

Call trace: vepdequeue+0x1c/0xe4 (P) usbepdequeue+0x14/0x20 ffsaio_cancel+0x24/0x34 _arm64sysiocancel+0xb0/0x124 doel0svc+0x68/0x100 el0svc+0x18/0x5c el0t64synchandler+0x98/0xdc el0t64sync+0x154/0x158

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64331.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b6a0ca11186759ad7045d68a5447b1e89f658384
Fixed
9858c91d9ee6a13c45311569039413729fc9b757
Fixed
1226293ec9bed3d4cc5b05eeeb811d315ca51652
Fixed
3750f75f29f99c0223601e2ee73ad084adec47bd
Fixed
d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97
Fixed
0025276175fbbe0dcbf3f84d090b0adee769e9d9
Fixed
347b59e9f96719d89b6ef555d02a18ada1a5846f
Fixed
0443e4416aa1ee97748d1ed904eaf3352c60045e
Fixed
c5371e0b91b24159a3ebaa61e70b0980bcf03c0a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64331.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64331.json"