Impact
The Linux kernel dwc3 USB controller driver contains a use–after–free flaw (CWE‑416) where issuing an EndTransfer command with the forceRM bit set leaves an aborted transfer active. If a subsequent StartTransfer writes to the same buffer after it has been unmapped during EndTransfer cleanup, an SMMU fault is triggered, potentially causing a kernel panic or another system failure.
Affected Systems
Systems running Linux kernels that include the dwc3 EndTransfer logic with forceRM set to 1 are vulnerable, specifically those using the DWC_usb31 v2.00a or v2.10a hardware controllers. All kernel versions prior to the patch that clears forceRM during EndTransfer may be affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, reflecting a low likelihood of immediate exploitation. The likely attack vector is an attacker forcing the host to issue EndTransfer with forceRM = 1, such as via a malicious USB device, but the exact conditions and required access are not specified in the source information.
OpenCVE Enrichment