PT-2026-57570 · Nuvoton · Numaker Hsusbd
CVE-2026-10668
·
Published
2026-07-12
·
Updated
2026-07-12
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Nuvoton NuMaker HSUSBD versions prior to 4.4.0
Description
The USB device-controller driver in the
drivers/usb/udc/udc numaker.c file unconditionally arms the control Data IN stage within the numaker hsusbd ep trigger() function. Since the hardware cannot disarm a control Data IN already armed for a previous transfer, a host that cancels an in-flight control transfer and subsequently issues a new SETUP packet can cause the driver to become out of sync. This results in the transmission of stale data and can cause the control endpoint to permanently return NAK (Negative Acknowledgment), which is a signal indicating the device is not ready to transfer data. A malicious or buggy host can repeatedly cancel and re-issue SETUP packets to wedge the USB control endpoint, leading to a denial of service where the device stops enumerating or responding until a USB reset or re-plug occurs.Recommendations
Update to version 4.4.0.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Numaker Hsusbd