Answer in brief
CVE-2026-64338 records a Medium severity (CVSS 5.5) vulnerability in USB: misc: uss720: unregister parport on probe failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04736c1bc32197f7d859e01a96ae80a16659931d <6bbb98bec71b577fda4f4b48f7aea5874b04a576 || >=4eaf2331a77996bbbaf2b824d452ac8ebda7e6e7 <93563243377f8e9b46cc94d9c4f06533dd31b141 || >=8fc246a8a456679993df565d3c9e3da28030ee43 <1712fd71a5aaf81e47c747f180535fa963ad7830 || >=10132ccf99f49b43aeb7470df50d72344a601ad6 <0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea || >=3295f1b866bfbcabd625511968e8a5c541f9ab32 <5e62d7857fd51b908b8371062ee839739a086bbe || >=3295f1b866bfbcabd625511968e8a5c541f9ab32 <729b68a5bad71220ae0914c8bdab9488ad5be6c8 || >=3295f1b866bfbcabd625511968e8a5c541f9ab32 <48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e || >=3295f1b866bfbcabd625511968e8a5c541f9ab32 <b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3 || 02d13616ca30014ed96302e51a5b0e17664e58bc || dff3b01e91a3df93063b03d0f8dd5c40546687ec || 489d77fbd66375972a380d207f7eb39b00c4a67b || >=5.10.221 <5.10.261 || >=5.15.162 <5.15.212 || >=6.1.96 <6.1.178 || >=6.6.36 <6.6.145 || >=4.19.317 <4.20 || >=5.4.279 <5.5 || >=6.9.7 <6.10 | 6bbb98bec71b577fda4f4b48f7aea5874b04a576, 93563243377f8e9b46cc94d9c4f06533dd31b141, 1712fd71a5aaf81e47c747f180535fa963ad7830, 0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea, 5e62d7857fd51b908b8371062ee839739a086bbe, 729b68a5bad71220ae0914c8bdab9488ad5be6c8, 48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e, b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3, 5.10.261, 5.15.212, 6.1.178, 6.6.145, 4.20, 5.5, 6.10 |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 11, 2026
In the Linux kernel, the following vulnerability has been resolved: USB: misc: uss720: unregister parport on probe failure uss720_probe() registers a parport before reading the 1284 register used to detect unsupported Belkin F5U002 adapters. If get_1284_register() fails, the error path drops the driver private data and the USB device reference, but leaves the parport device registered. Leaving the port registered is more than a private allocation leak: parport_register_port() has already reserved a parport number and registered the parport bus device, while pp->private_data still points at the private data that the common error path is about to release. Undo the pre-announce registration in the get_1284_register() failure branch before jumping to the common private-data cleanup path. Clear priv->pp first, matching the disconnect path and avoiding a stale pointer in the private data. This issue was identified during our ongoing static-analysis research while reviewing kernel code.
Quoted source text, attributed separately from HOL analysis.