Answer in brief
CVE-2026-64583 records a High severity (CVSS 7.8) vulnerability in usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=efed421a94e62a7ddbc76acba4312b70e4be958f <1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <f6fc21ec7ccd83726ba766d73d0b8cc03e726475 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <dcf3e2f164435b5844706cb8eefef29ebee0eedb || >=efed421a94e62a7ddbc76acba4312b70e4be958f <d4964a74717107697999f48bcb4e80a9c0679a27 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb | 1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8, f6fc21ec7ccd83726ba766d73d0b8cc03e726475, dcf3e2f164435b5844706cb8eefef29ebee0eedb, d4964a74717107697999f48bcb4e80a9c0679a27, 0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb |
| Linux/Linuxgeneric | 3.19 | Not reported |
| Linux/Linuxgeneric | >=efed421a94e62a7ddbc76acba4312b70e4be958f <0b0b76e31b3991a899ae724eb97d359de0c0f1b1 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <3fe181952b8a1aeb167d4503c794c0f5050f08ed || >=efed421a94e62a7ddbc76acba4312b70e4be958f <1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <f6fc21ec7ccd83726ba766d73d0b8cc03e726475 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <dcf3e2f164435b5844706cb8eefef29ebee0eedb || >=efed421a94e62a7ddbc76acba4312b70e4be958f <d4964a74717107697999f48bcb4e80a9c0679a27 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb | 0b0b76e31b3991a899ae724eb97d359de0c0f1b1, 3fe181952b8a1aeb167d4503c794c0f5050f08ed, 1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8, f6fc21ec7ccd83726ba766d73d0b8cc03e726475, dcf3e2f164435b5844706cb8eefef29ebee0eedb, d4964a74717107697999f48bcb4e80a9c0679a27, 0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb |
| Linux/Linuxgeneric | >=efed421a94e62a7ddbc76acba4312b70e4be958f <eac1107e54679db2df2c36d8bba3b66d3ab6cbcd || >=efed421a94e62a7ddbc76acba4312b70e4be958f <0b0b76e31b3991a899ae724eb97d359de0c0f1b1 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <3fe181952b8a1aeb167d4503c794c0f5050f08ed || >=efed421a94e62a7ddbc76acba4312b70e4be958f <1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <f6fc21ec7ccd83726ba766d73d0b8cc03e726475 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <dcf3e2f164435b5844706cb8eefef29ebee0eedb || >=efed421a94e62a7ddbc76acba4312b70e4be958f <d4964a74717107697999f48bcb4e80a9c0679a27 || >=efed421a94e62a7ddbc76acba4312b70e4be958f <0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb | eac1107e54679db2df2c36d8bba3b66d3ab6cbcd, 0b0b76e31b3991a899ae724eb97d359de0c0f1b1, 3fe181952b8a1aeb167d4503c794c0f5050f08ed, 1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8, f6fc21ec7ccd83726ba766d73d0b8cc03e726475, dcf3e2f164435b5844706cb8eefef29ebee0eedb, d4964a74717107697999f48bcb4e80a9c0679a27, 0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 23, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only after bdc_remove() returns. devm releases resources in reverse LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -> bdc_mem_free() manually before returning: bdc_udc_exit() tears down individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -> bdc_mem_free() frees and NULLs the DMA-coherent status-report ring (bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. Both happen while the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED) remains deliverable in the window up to the post-remove devm free_irq(). On receipt of a shared interrupt in that window, bdc_udc_interrupt() dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA) and dispatches sr_handler callbacks that index into bdc_ep_array, causing a NULL-deref or use-after-free. The same window affects the delayed_work bdc->func_wake_notify, which is armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change() -> schedule_delayed_work() and may self-rearm from its own callback bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a queued work item that fires after bdc_remove() returns and the bdc structure is devm-freed dereferences freed memory. Replace devm_request_irq() with request_irq() and add an explicit free_irq(bdc->irq, bdc) in bdc_remove(). Clear BDC_GIE before free_irq() to stop the device from asserting interrupts, then free_irq() drains any in-flight handler, then cancel_delayed_work_sync() drains the func_wake_notify delayed work. This ordering ensures the IRQ handler and delayed work cannot interfere with the subsequent endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the matching free_irq() into the bdc_udc_init() error path so the IRQ is released on probe failure, and route the bdc_init_ep() failure through err0 instead of returning directly. This issue was found by an in-house static analysis tool.
Quoted source text, attributed separately from HOL analysis.