PT-2026-93671 · Linux · Linux Kernel
CVE-2026-90030
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the usb dwc3 driver where the
forceRM bit of the DEPCMD register is set to 1 when issuing an EndTransfer command to stop an active transfer. On DWC usb31 v2.00a and v2.10a controllers, this causes transfers aborted via the ep dequeue path to remain active after the EndTransfer completion. When a subsequent StartTransfer is issued on the same endpoint, it triggers writes from the previously aborted transfer. This leads to an SMMU (System Memory Management Unit) fault because the transfer buffer is unmapped during the EndTransfer cleanup process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel