vulnerability in Linux kernel affecting xHCI USB controller
CVE-2026-90015

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90015?

A vulnerability in the Linux kernel related to the xHCI USB controller can lead to data integrity issues during large and fragmented bulk transfers. When a transfer descriptor (TD) doesn't align with the endpoint's maximum packet size, the handling of bounce buffers may fail for transfers crossing multiple ring segments. This can result in incomplete or stale data being copied into the destination buffer without error, causing silent data corruption. The issue is exacerbated during complex transfer scenarios, particularly with USB mass storage devices, potentially leading to the misreporting of metadata corruption. Proper remediation involves careful management of segment boundaries and ensuring all bounce buffers are accurately processed.

Affected Version(s)

Linux f9c589e142d04b8a19eb382162f804d17102b5ed

Linux f9c589e142d04b8a19eb382162f804d17102b5ed

Linux f9c589e142d04b8a19eb382162f804d17102b5ed

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.