目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-64331— usbip vudc: vep_dequeue()空指针解引用漏洞

AI Predicted 4.4 Difficulty: Hard EPSS 0.18% · P7

Affected Version Matrix 18

ベンダープロダクトVersion Rangeステータス
LinuxLinuxb6a0ca11186759ad7045d68a5447b1e89f658384< 9858c91d9ee6a13c45311569039413729fc9b757affected
b6a0ca11186759ad7045d68a5447b1e89f658384< 1226293ec9bed3d4cc5b05eeeb811d315ca51652affected
b6a0ca11186759ad7045d68a5447b1e89f658384< 3750f75f29f99c0223601e2ee73ad084adec47bdaffected
b6a0ca11186759ad7045d68a5447b1e89f658384< d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97affected
b6a0ca11186759ad7045d68a5447b1e89f658384< 0025276175fbbe0dcbf3f84d090b0adee769e9d9affected
b6a0ca11186759ad7045d68a5447b1e89f658384< 347b59e9f96719d89b6ef555d02a18ada1a5846faffected
b6a0ca11186759ad7045d68a5447b1e89f658384< 0443e4416aa1ee97748d1ed904eaf3352c60045eaffected
b6a0ca11186759ad7045d68a5447b1e89f658384< c5371e0b91b24159a3ebaa61e70b0980bcf03c0aaffected
… +10 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-64331の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
usbip: vudc: fix NULL deref in vep_dequeue()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: fix NULL deref in vep_dequeue() vep_alloc_request() wasn't initializing vrequest->udc, so cancellations on the FunctionFS AIO path were arriving in vep_dequeue without a valid UDC reference. Since vrequest->udc is never actually properly used anywhere, we opt to remove it, and update vep_dequeue to obtain a reference to the udc with ep_to_vudc(), consistent with the other vep_ ops. AFAICT this bug has existed for ~10 years. Seems that nobody has really stressed the FunctionFS AIO path on usbip's vudc. I tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints via AIO. Before the fix, running `usbip attach` from the host would cause the guest to oops with the following backtrace: Call trace: vep_dequeue+0x1c/0xe4 (P) usb_ep_dequeue+0x14/0x20 ffs_aio_cancel+0x24/0x34 __arm64_sys_io_cancel+0xb0/0x124 do_el0_svc+0x68/0x100 el0_svc+0x18/0x5c el0t_64_sync_handler+0x98/0xdc el0t_64_sync+0x154/0x158
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux b6a0ca11186759ad7045d68a5447b1e89f658384 ~ 9858c91d9ee6a13c45311569039413729fc9b757 -
LinuxLinux 4.7 -

II. CVE-2026-64331の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-64331のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-64331 补丁与修复 (8)

Same Patch Batch · Linux · 2026-07-25 · 274 CVEs total

CVE-2026-64342USB: iowarrior: fix use-after-free on disconnect
CVE-2026-64357xfs: fix exchmaps reservation limit check
CVE-2026-64358media: mtk-jpeg: cancel workqueue on release for supported platforms only
CVE-2026-64356xfs: fix memory leak in xfs_dqinode_metadir_create()
CVE-2026-64354bpf: Validate BTF repeated field counts before expansion
CVE-2026-64355bpf: Reject fragmented frames in devmap
CVE-2026-64352bpf: Allow LPM map access from sleepable BPF programs
CVE-2026-64353bpf: Keep dynamic inner array lookups nullable
CVE-2026-64351net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
CVE-2026-64350usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
CVE-2026-64349usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
CVE-2026-64348usb: free iso schedules on failed submit
CVE-2026-64347usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
CVE-2026-64346usb: gadget: udc: Fix use-after-free in gadget_match_driver
CVE-2026-64345usb: gadget: f_printer: take kref only for successful open
CVE-2026-64344USB: idmouse: fix use-after-free on disconnect race
CVE-2026-64343USB: ldusb: fix use-after-free on disconnect race
CVE-2026-64341USB: iowarrior: fix use-after-free on disconnect race
CVE-2026-64330usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
CVE-2026-64328usb: gadget: f_fs: Fix DMA fence leak

Showing 20 of 274 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-64331へのコメント

まだコメントはありません


コメントを残す