CVE-2026-64349

Source
https://cve.org/CVERecord?id=CVE-2026-64349
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64349.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64349
Downstream
Published
2026-07-25T08:50:09.647Z
Modified
2026-07-27T04:03:21.644198270Z
Summary
usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: fix dwc3readl() and dwc3writel() calls in dwc3ulpisetup()

The dwc3ulpisetup() calls the register read and write calls with dwc3->regs when both these calls take the dwc3 structure directly.

Chnage these two calls to fix the following sparse warning, and possibly a nasty bug in the dwc3ulpisetup() code:

drivers/usb/dwc3/core.c:796:45: warning: incorrect type in argument 1 (different address spaces) drivers/usb/dwc3/core.c:796:45: expected struct dwc3 *dwc drivers/usb/dwc3/core.c:796:45: got void [noderef] __iomem *regs drivers/usb/dwc3/core.c:798:40: warning: incorrect type in argument 1 (different address spaces) drivers/usb/dwc3/core.c:798:40: expected struct dwc3 *dwc drivers/usb/dwc3/core.c:798:40: got void [noderef] __iomem *regs

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64349.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
476ee6389120e1900290b46081b3a12b54e05672
Fixed
41a4e80d5af04855e68ac88f5e2cd07fa67287f8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9accc68b1cf0a2b220f51d53641128bb32598070
Fixed
4349e487a1149ff33b65d53427b8aca57f2e4578
Fixed
e0f844d9d74200d311c6438a0f04270834ba5365
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.18.32
Fixed
6.18.40

Affected versions

v6.*
v6.18.32
v6.18.33
v6.18.34
v6.18.35
v6.18.36
v6.18.37
v6.18.38
v6.18.39

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64349.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64349.json"