PT-2026-94914 · Linux · Linux Kernel

CVE-2026-93118

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.16
Description An issue exists in the aspeed udc gadget driver where the ast udc probe() function allocates a coherent DMA (Direct Memory Access) buffer to serve as the backing store for endpoint buffers. Because the ast udc init ep() function derives per-endpoint buffer pointers from udc->ep0 buf without verifying if the allocation was successful, a failed allocation leads to a null pointer dereference during the probe process.
Recommendations Update the Linux kernel to version 6.16 or later.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102150
CVE-2026-93118
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel