CVE-2026-97483
Możliwe zablokowanie w jądrze Linux podczas transferów kontrolnych USB może prowadzić do awarii systemu.
In the Linux kernel, the following vulnerability has been resolved: usb: core: hcd: fix possible deadlock in rh control transfers >From within the SCSI error handler memory allocations must not trigger IO. Handling errors in UAS and the storage driver may involve resetting a device. The thread doing the reset itself relies on VM magic. However, that is insufficient, as resetting a device involves resuming it. Resumption as well as resetting involves conrol transfers to the parent of the device to be reset. That may be a root hub. Hence usbcore must heed the flags passed to usb_submit_urb() processing control transfers to root hubs. The problem exist since the storage driver has been merged.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:25 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:58 UTC |
- https://git.kernel.org/stable/c/549672a3fb6b36ea408238f89ecf9f41d2da6225 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/8461eda5af77c44d216cec66455bd5b01ee35c9a (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/8f82fc3d72e5feb7a1efae94b51b431c5bf41c86 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/936b08d87c667031725bcc753007e7c1182548c6 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/d0291fb4d91982d9f6a680bf759ff0555d351ecb (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/d5559f43d76b398392b26a15cbc16d731969cd1c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fff917c85d37a294397c5440a795591ca9d6b602 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)