PT-2026-105007 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
usbip: vhci hcd: fix NULL deref in status show vhci
platform get drvdata() can return NULL if a VHCI host controller's
probe failed (e.g. due to USB bus number exhaustion). status show vhci()
checked for a NULL pdev but not for a NULL hcd returned by
platform get drvdata(). Passing NULL to hcd to vhci hcd() does not
return NULL - it returns a pointer offset of 0x260, causing a NULL
pointer dereference when that value is subsequently dereferenced.
Add a NULL check on hcd before calling hcd to vhci hcd(). Move
status show not ready() above status show vhci() to make it callable
from the new error path without a forward declaration.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel