Linux Kernel Vulnerability in DWC3 USB Controllers
CVE-2026-90030

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90030?

A vulnerability in the Linux kernel's DWC3 USB controllers arises due to an incorrect implementation of the EndTransfer command. The forceRM bit in the DEPCMD register, which was previously set to 1 according to outdated programming guidelines, can lead to unwanted behaviors during active data transfers. When EndTransfer is issued with forceRM=1, aborted transfers may remain active, resulting in subsequent commands causing system faults. To mitigate this issue, the forceRM bit should be cleared when issuing the EndTransfer command, aligning the implementation with updated programming recommendations and ensuring reliable transfer termination.

Affected Version(s)

Linux 1e43c86d84fb0503e82a143e017f35421498fc1a < 0afe5c31612de3d18cc6d16e616da4a48ba1e5a2

Linux 1e43c86d84fb0503e82a143e017f35421498fc1a

Linux 1e43c86d84fb0503e82a143e017f35421498fc1a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.