๐Ÿ” CVE Alert

CVE-2026-31615

UNKNOWN 0.0

usb: gadget: renesas_usb3: validate endpoint index in standard request handlers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: renesas_usb3: validate endpoint index in standard request handlers The GET_STATUS and SET/CLEAR_FEATURE handlers extract the endpoint number from the host-supplied wIndex without any sort of validation. Fix this up by validating the number of endpoints actually match up with the number the device has before attempting to dereference a pointer based on this math. This is just like what was done in commit ee0d382feb44 ("usb: gadget: aspeed_udc: validate endpoint index for ast udc") for the aspeed driver.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Apr 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < adb8014599fdf0818d3d93f1f74e06cd0bdec08d 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 44216e3dd4455b798899b50eedb0ec3831dff8e0 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 37f430b2240655e6b0199a92aa1057e4d621be51 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e3d42598f2995cdc07b7779874e7c5f8a1b773db
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/adb8014599fdf0818d3d93f1f74e06cd0bdec08d git.kernel.org: https://git.kernel.org/stable/c/44216e3dd4455b798899b50eedb0ec3831dff8e0 git.kernel.org: https://git.kernel.org/stable/c/37f430b2240655e6b0199a92aa1057e4d621be51 git.kernel.org: https://git.kernel.org/stable/c/e3d42598f2995cdc07b7779874e7c5f8a1b773db