usb: mtu3: unmap request DMA on queue failure
Published Jul 25, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails.
Normal completion and dequeue paths unmap requests from mtu3_req_complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.10
- Version 5.10.261StatusunaffectedConstraints<=5.10.*
- Version 5.15.212StatusunaffectedConstraints<=5.15.*
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.96StatusunaffectedConstraints<=6.12.*
- Version 6.18.39StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.4StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.10 · < 5.10.261
- ≥ 5.11 · < 5.15.212
- ≥ 5.16 · < 6.1.178
- ≥ 6.2 · < 6.6.145
- ≥ 6.7 · < 6.12.96
- ≥ 6.13 · < 6.18.39
- ≥ 6.19 · < 7.1.4
- 7.2
- 7.2
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-64337 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507230 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48881 Advisory
- https://git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09 Patch
- https://git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c Patch
- https://git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98 Patch
- https://git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236 Patch
- https://git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74 Patch
- https://git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1 Patch
- https://git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5 Patch
- https://git.kernel.org/stable/c/f3c4026524d3660c73ef2838b99776d37631e039 Patch
- https://lore.kernel.org/linux-cve-announce/2026072515-CVE-2026-64337-79eb@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64337
- https://www.cve.org/CVERecord?id=CVE-2026-64337
Change history (0)
No recorded changes yet.