Remote Code Execution Vulnerability in Linux Kernel's USB Media Driver
CVE-2026-64240

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64240?

A vulnerability has been identified in the Linux kernel's USB media drivers, specifically involving the igorplugusb driver. A recent change in the control request struct has led to a situation where the USB core misinterprets the setup packet. This occurs due to the driver using an incorrect pointer for the URB setup, potentially causing invalid requests and warnings during operation. Implementing the correct pointer reference can mitigate this issue, ensuring that the control requests are handled properly and reducing the risk of unforeseen system behavior.

Affected Version(s)

Linux bc04b8633b375af6ac8a8bb615258b80fe06cdaa

Linux 81f0fb813e4bf28b3ca28dc218938a32eb48f740 < 2243ad78ce64d344754260533ae7730c2174a34a

Linux 0e84aa8fc23c7578f105e3a2160f9d0aa2bed79a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.