Back

MEDIUM

usb: mtu3: unmap request DMA on queue failure

Published Jul 25, 2026

Description

mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails.

Normal completion and dequeue paths unmap requests from mtu3_req_complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 25, 2026
Updated Aug 17, 2026
Reserved Jul 19, 2026
NVD
Status Analyzed
Modified Sep 3, 2026
Red Hat
Severity n/a
Public date Jul 25, 2026
ENISA EUVD
Assigner Linux
Published Jul 25, 2026
Updated Aug 17, 2026
Exploited since n/a
EUVD-2026-48881