Use-after-free Vulnerability in Linux Kernel's USB c67x00 Driver
CVE-2026-80826
Currently unrated
What is CVE-2026-80826?
A use-after-free vulnerability has been identified in the USB c67x00 driver within the Linux kernel. This issue arises in scenarios where Transmission Descriptor (TD) creation fails for the last packet of an isochronous USB Request Block (URB). The function c67x00_add_iso_urb() prematurely gives back the URB without appropriately updating the endpoint scheduling state, leading to potential accesses of freed memory in c67x00_giveback_urb(). This can result in errant behavior or crashes, impacting the stability and security of systems that utilize affected versions of the Linux kernel.
Affected Version(s)
Linux e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d
Linux e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d
Linux e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d