Answer in brief
CVE-2024-26659 records a Unknown severity vulnerability in xhci: handle isoc Babble and Buffer Overrun events properly. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-26659 records a Unknown severity vulnerability in xhci: handle isoc Babble and Buffer Overrun events properly. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04e51901dd44f40a5a385ced897f6bca87d5f40a <696e4112e5c1ee61996198f0ebb6ca3fab55166e || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <2aa7bcfdbb46241c701811bbc0d64d7884e3346c || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <2e3ec80ea7ba58bbb210e83b5a0afefee7c171d3 || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <f5e7ffa9269a448a720e21f1ed1384d118298c97 || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <418456c0ce56209610523f21734c5612ee634134 || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <7c4650ded49e5b88929ecbbb631efb8b0838e811 | 696e4112e5c1ee61996198f0ebb6ca3fab55166e, 2aa7bcfdbb46241c701811bbc0d64d7884e3346c, 2e3ec80ea7ba58bbb210e83b5a0afefee7c171d3, f5e7ffa9269a448a720e21f1ed1384d118298c97, 418456c0ce56209610523f21734c5612ee634134, 7c4650ded49e5b88929ecbbb631efb8b0838e811 |
| Linux/Linuxgeneric | 2.6.36 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Apr 2, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: xhci: handle isoc Babble and Buffer Overrun events properly xHCI 4.9 explicitly forbids assuming that the xHC has released its ownership of a multi-TRB TD when it reports an error on one of the early TRBs. Yet the driver makes such assumption and releases the TD, allowing the remaining TRBs to be freed or overwritten by new TDs. The xHC should also report completion of the final TRB due to its IOC flag being set by us, regardless of prior errors. This event cannot be recognized if the TD has already been freed earlier, resulting in "Transfer event TRB DMA ptr not part of current TD" error message. Fix this by reusing the logic for processing isoc Transaction Errors. This also handles hosts which fail to report the final completion. Fix transfer length reporting on Babble errors. They may be caused by device malfunction, no guarantee that the buffer has been filled.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04e51901dd44f40a5a385ced897f6bca87d5f40a <696e4112e5c1ee61996198f0ebb6ca3fab55166e || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <2aa7bcfdbb46241c701811bbc0d64d7884e3346c || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <2e3ec80ea7ba58bbb210e83b5a0afefee7c171d3 || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <f5e7ffa9269a448a720e21f1ed1384d118298c97 || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <418456c0ce56209610523f21734c5612ee634134 || >=04e51901dd44f40a5a385ced897f6bca87d5f40a <7c4650ded49e5b88929ecbbb631efb8b0838e811 | 696e4112e5c1ee61996198f0ebb6ca3fab55166e, 2aa7bcfdbb46241c701811bbc0d64d7884e3346c, 2e3ec80ea7ba58bbb210e83b5a0afefee7c171d3, f5e7ffa9269a448a720e21f1ed1384d118298c97, 418456c0ce56209610523f21734c5612ee634134, 7c4650ded49e5b88929ecbbb631efb8b0838e811 |
| Linux/Linuxgeneric | 2.6.36 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Apr 2, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: xhci: handle isoc Babble and Buffer Overrun events properly xHCI 4.9 explicitly forbids assuming that the xHC has released its ownership of a multi-TRB TD when it reports an error on one of the early TRBs. Yet the driver makes such assumption and releases the TD, allowing the remaining TRBs to be freed or overwritten by new TDs. The xHC should also report completion of the final TRB due to its IOC flag being set by us, regardless of prior errors. This event cannot be recognized if the TD has already been freed earlier, resulting in "Transfer event TRB DMA ptr not part of current TD" error message. Fix this by reusing the logic for processing isoc Transaction Errors. This also handles hosts which fail to report the final completion. Fix transfer length reporting on Babble errors. They may be caused by device malfunction, no guarantee that the buffer has been filled.
Quoted source text, attributed separately from HOL analysis.