PT-2026-93671 · Linux · Linux Kernel

CVE-2026-90030

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the usb dwc3 driver where the forceRM bit of the DEPCMD register is set to 1 when issuing an EndTransfer command to stop an active transfer. On DWC usb31 v2.00a and v2.10a controllers, this causes transfers aborted via the ep dequeue path to remain active after the EndTransfer completion. When a subsequent StartTransfer is issued on the same endpoint, it triggers writes from the previously aborted transfer. This leads to an SMMU (System Memory Management Unit) fault because the transfer buffer is unmapped during the EndTransfer cleanup process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101493
CVE-2026-90030
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel