In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: composite: fix dead empty check in the USBDTOTG handler
The OTG branch of composite_setup() falls back to the first configuration when none is selected:
if (cdev->config)
config = cdev->config;
else
config = list_first_entry(&cdev->configs,
struct usb_configuration, list);
if (!config)
goto done;
...
memcpy(req->buf, config->descriptors[0], value);
listfirstentry() never returns NULL. On an empty list it returns container_of() of the list head. So the "if (!config)" check is dead.
When cdev->configs is empty, config points at the head inside struct usbcompositedev. config->descriptors[0] reads whatever sits at that offset. The memcpy copies up to w_length bytes of it into the response buffer.
cdev->configs can be empty in two cases. One is a teardown race on gadget unbind with a control transfer in flight. The other is a driver that sets is_otg before it adds a config. A reproducer that holds cdev->configs empty triggers a KASAN fault in this branch.
Use listfirstentryornull() so the existing check does its job.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64347.json"
}