Answer in brief
CVE-2026-63927 records a Unknown severity vulnerability in usb: dwc2: Fix use after free in debug code. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-63927 records a Unknown severity vulnerability in usb: dwc2: Fix use after free in debug code. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7359d482eb4d3967cc8be354405ae6be6eaf732c <d5fc183ed614aeba6779cc992325be560f9a4451 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <63b0dafa676aad4d0c3f01a61ad8e2990907660c || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <0584af4fe40fa5e254a05d69ce658746de641708 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <a15eeeceb94cbc04edef395e4d777ff554bdc27d || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <84ea928ed584756e59c6ac09736f12d1db95ded0 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <6d0b79d1d1118145e48a68192b6d733e39387053 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <9ea06a3fbf9f16e0d98c52cb3b99642be15ec281 | d5fc183ed614aeba6779cc992325be560f9a4451, 63b0dafa676aad4d0c3f01a61ad8e2990907660c, 9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913, 0584af4fe40fa5e254a05d69ce658746de641708, a15eeeceb94cbc04edef395e4d777ff554bdc27d, 84ea928ed584756e59c6ac09736f12d1db95ded0, 6d0b79d1d1118145e48a68192b6d733e39387053, 9ea06a3fbf9f16e0d98c52cb3b99642be15ec281 |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix use after free in debug code We're not allowed to dereference "urb" after calling usb_hcd_giveback_urb() so save the urb->status ahead of time.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7359d482eb4d3967cc8be354405ae6be6eaf732c <d5fc183ed614aeba6779cc992325be560f9a4451 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <63b0dafa676aad4d0c3f01a61ad8e2990907660c || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <0584af4fe40fa5e254a05d69ce658746de641708 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <a15eeeceb94cbc04edef395e4d777ff554bdc27d || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <84ea928ed584756e59c6ac09736f12d1db95ded0 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <6d0b79d1d1118145e48a68192b6d733e39387053 || >=7359d482eb4d3967cc8be354405ae6be6eaf732c <9ea06a3fbf9f16e0d98c52cb3b99642be15ec281 | d5fc183ed614aeba6779cc992325be560f9a4451, 63b0dafa676aad4d0c3f01a61ad8e2990907660c, 9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913, 0584af4fe40fa5e254a05d69ce658746de641708, a15eeeceb94cbc04edef395e4d777ff554bdc27d, 84ea928ed584756e59c6ac09736f12d1db95ded0, 6d0b79d1d1118145e48a68192b6d733e39387053, 9ea06a3fbf9f16e0d98c52cb3b99642be15ec281 |
| Linux/Linuxgeneric | 3.10 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix use after free in debug code We're not allowed to dereference "urb" after calling usb_hcd_giveback_urb() so save the urb->status ahead of time.
Quoted source text, attributed separately from HOL analysis.