Description
In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: clear forceRM when issuing EndTransfer

The forceRM bit of the DEPCMD register controls the behavior of the
EndTransfer command used to stop an active transfer. Older DWC3
programming guide revisions recommended setting forceRM=1 when
issuing EndTransfer. Newer programming guide revisions recommend
issuing EndTransfer with forceRM cleared.

With forceRM=1 on DWC_usb31 v2.00a and v2.10a controllers, a transfer
aborted through the ep_dequeue path was observed to remain active
after EndTransfer completion. A subsequent StartTransfer issued on the
same endpoint triggered writes associated with the aborted transfer.
This resulted in an SMMU fault because the transfer buffer had already
been unmapped during EndTransfer command-completion cleanup.

Using forceRM=0 eliminates the issue. Although older DWC3 programming
guide revisions recommended setting forceRM=1, no issues are known
from using forceRM=0. Clear forceRM when issuing EndTransfer to provide
consistent EndTransfer behavior and align with newer programming guide
recommendations.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash (SMMU fault)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel dwc3 USB controller driver contains a use–after–free flaw (CWE‑416) where issuing an EndTransfer command with the forceRM bit set leaves an aborted transfer active. If a subsequent StartTransfer writes to the same buffer after it has been unmapped during EndTransfer cleanup, an SMMU fault is triggered, potentially causing a kernel panic or another system failure.

Affected Systems

Systems running Linux kernels that include the dwc3 EndTransfer logic with forceRM set to 1 are vulnerable, specifically those using the DWC_usb31 v2.00a or v2.10a hardware controllers. All kernel versions prior to the patch that clears forceRM during EndTransfer may be affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, yet the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, reflecting a low likelihood of immediate exploitation. The likely attack vector is an attacker forcing the host to issue EndTransfer with forceRM = 1, such as via a malicious USB device, but the exact conditions and required access are not specified in the source information.

Generated by OpenCVE AI on September 18, 2026 at 08:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that fixes the dwc3 EndTransfer forceRM bug.
  • If the kernel cannot be updated immediately, reconfigure the driver or firmware to clear the forceRM bit before issuing EndTransfer, following the newer programming guide recommendations.
  • As a temporary measure, disable or replace the affected USB 3.0 controller, or prevent the use of the EndTransfer command on the implicated endpoint.

Generated by OpenCVE AI on September 18, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when issuing EndTransfer The forceRM bit of the DEPCMD register controls the behavior of the EndTransfer command used to stop an active transfer. Older DWC3 programming guide revisions recommended setting forceRM=1 when issuing EndTransfer. Newer programming guide revisions recommend issuing EndTransfer with forceRM cleared. With forceRM=1 on DWC_usb31 v2.00a and v2.10a controllers, a transfer aborted through the ep_dequeue path was observed to remain active after EndTransfer completion. A subsequent StartTransfer issued on the same endpoint triggered writes associated with the aborted transfer. This resulted in an SMMU fault because the transfer buffer had already been unmapped during EndTransfer command-completion cleanup. Using forceRM=0 eliminates the issue. Although older DWC3 programming guide revisions recommended setting forceRM=1, no issues are known from using forceRM=0. Clear forceRM when issuing EndTransfer to provide consistent EndTransfer behavior and align with newer programming guide recommendations.
Title usb: dwc3: clear forceRM when issuing EndTransfer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:57:02.429Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:16.070

Modified: 2026-10-03T11:17:46.047

Link: CVE-2026-90030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses