Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: aspeed_udc: check endpoint DMA allocation

ast_udc_probe() allocates a coherent DMA buffer used as the backing store
for endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer
pointers from udc->ep0_buf, so a failed allocation is dereferenced during
probe.

Check the allocation before endpoint setup. The existing probe error path
called ast_udc_remove(), which unregisters the gadget unconditionally and
is not safe before usb_add_gadget_udc() succeeds. Add a local cleanup
helper for probe failures so pre-registration failures only unwind the
resources that were actually initialized.

This was found by a local static analysis checker for unchecked allocator
returns while scanning Linux 6.16. The change was checked by applying it
to current mainline and by running checkpatch. I do not have access to
Aspeed UDC hardware, so no runtime testing was performed.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service via kernel crash
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the Linux kernel’s aspeed_udc driver allows a failed DMA buffer allocation to be dereferenced during device probe, leading to a null pointer dereference that crashes the kernel. This results in a denial of service because the operating system becomes unstable or stops responding. The weakness is a classic unchecked return value error that can corrupt kernel memory, potentially preventing normal system operation. The impact is limited to the system hosting the affected kernel; an attacker would need to control or connect to the USB device to trigger the crash.

Affected Systems

All Linux kernel deployments that include the Aspeed Universal Device Controller (UDC) driver, particularly on boards using Aspeed hardware, are affected. The issue exists in kernel versions running the unpatched aspeed_udc code, which prior to the 6.16 mainline update contained the bug. End‑users running older kernels without the fix should consider updating the kernel or removing the driver if the USB gadget functionality is not required.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector would be local and would require physical or direct USB access to the affected device to trigger the fault. No public exploit is known, and the risk is largely mitigated by the low exploitation probability and the necessity of a direct device connection.

Generated by OpenCVE AI on September 19, 2026 at 07:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the fixed aspeed_udc driver (e.g., 6.16 or newer).
  • If upgrading is not possible, apply the patch that checks DMA allocation before use in the aspeed_udc driver source and rebuild the kernel or load the patched module.
  • If the USB gadget feature is not required, disable or remove the aspeed_udc driver from the system to eliminate the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 07:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: check endpoint DMA allocation ast_udc_probe() allocates a coherent DMA buffer used as the backing store for endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer pointers from udc->ep0_buf, so a failed allocation is dereferenced during probe. Check the allocation before endpoint setup. The existing probe error path called ast_udc_remove(), which unregisters the gadget unconditionally and is not safe before usb_add_gadget_udc() succeeds. Add a local cleanup helper for probe failures so pre-registration failures only unwind the resources that were actually initialized. This was found by a local static analysis checker for unchecked allocator returns while scanning Linux 6.16. The change was checked by applying it to current mainline and by running checkpatch. I do not have access to Aspeed UDC hardware, so no runtime testing was performed.
Title usb: gadget: aspeed_udc: check endpoint DMA allocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:25.186Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:06.427

Modified: 2026-09-17T17:18:06.427

Link: CVE-2026-93118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses