Answer in brief
CVE-2026-68370 records a Unknown severity vulnerability in usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e2b2740f1242bc70b5b46da2cdbbaa419f490e59 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <67b589d09a96882d56842dced5698ed8dd06ce45 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e239ea91b48180ed48a86ac25643832a02c88456 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e24b33618231034bf01dfaff4fd3409d4b4d5b2e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d5e5cd3654d2b5359a12ea6586120f05b28634ee | e2b2740f1242bc70b5b46da2cdbbaa419f490e59, 67b589d09a96882d56842dced5698ed8dd06ce45, e239ea91b48180ed48a86ac25643832a02c88456, e24b33618231034bf01dfaff4fd3409d4b4d5b2e, d5e5cd3654d2b5359a12ea6586120f05b28634ee |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the "emulated single-request FIFO" fast-path in dummy_queue() reuses for small IN transfers: it copies the caller's request into it (req->req = *_req) and queues it, treating list_empty(&fifo_req.queue) as "the slot is free". The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(&req->queue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req->complete(). But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req->req = *_req -- overwriting req->complete while dummy_timer is mid-calling it. The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it. Add a fifo_req_busy bit covering the shared request's whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(&fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-request giveback sites. The shared slot can no longer be reused until its completion callback has finished.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68370 records a Unknown severity vulnerability in usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e2b2740f1242bc70b5b46da2cdbbaa419f490e59 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <67b589d09a96882d56842dced5698ed8dd06ce45 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e239ea91b48180ed48a86ac25643832a02c88456 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e24b33618231034bf01dfaff4fd3409d4b4d5b2e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d5e5cd3654d2b5359a12ea6586120f05b28634ee | e2b2740f1242bc70b5b46da2cdbbaa419f490e59, 67b589d09a96882d56842dced5698ed8dd06ce45, e239ea91b48180ed48a86ac25643832a02c88456, e24b33618231034bf01dfaff4fd3409d4b4d5b2e, d5e5cd3654d2b5359a12ea6586120f05b28634ee |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the "emulated single-request FIFO" fast-path in dummy_queue() reuses for small IN transfers: it copies the caller's request into it (req->req = *_req) and queues it, treating list_empty(&fifo_req.queue) as "the slot is free". The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(&req->queue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req->complete(). But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req->req = *_req -- overwriting req->complete while dummy_timer is mid-calling it. The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it. Add a fifo_req_busy bit covering the shared request's whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(&fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-request giveback sites. The shared slot can no longer be reused until its completion callback has finished.
Quoted source text, attributed separately from HOL analysis.