Answer in brief
CVE-2026-68370 records a High severity (CVSS 7.8) vulnerability in usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e2b2740f1242bc70b5b46da2cdbbaa419f490e59 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <67b589d09a96882d56842dced5698ed8dd06ce45 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e239ea91b48180ed48a86ac25643832a02c88456 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e24b33618231034bf01dfaff4fd3409d4b4d5b2e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d5e5cd3654d2b5359a12ea6586120f05b28634ee | e2b2740f1242bc70b5b46da2cdbbaa419f490e59, 67b589d09a96882d56842dced5698ed8dd06ce45, e239ea91b48180ed48a86ac25643832a02c88456, e24b33618231034bf01dfaff4fd3409d4b4d5b2e, d5e5cd3654d2b5359a12ea6586120f05b28634ee |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <16a685172abc9233728830e27d26ffa778975b51 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <95f30a21612cc65761c58ba044b1767699437317 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3cab0e5498d0fbb21fe1a9181f7bda9a844a697e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e2b2740f1242bc70b5b46da2cdbbaa419f490e59 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <67b589d09a96882d56842dced5698ed8dd06ce45 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e239ea91b48180ed48a86ac25643832a02c88456 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e24b33618231034bf01dfaff4fd3409d4b4d5b2e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d5e5cd3654d2b5359a12ea6586120f05b28634ee | 16a685172abc9233728830e27d26ffa778975b51, 95f30a21612cc65761c58ba044b1767699437317, 3cab0e5498d0fbb21fe1a9181f7bda9a844a697e, e2b2740f1242bc70b5b46da2cdbbaa419f490e59, 67b589d09a96882d56842dced5698ed8dd06ce45, e239ea91b48180ed48a86ac25643832a02c88456, e24b33618231034bf01dfaff4fd3409d4b4d5b2e, d5e5cd3654d2b5359a12ea6586120f05b28634ee |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the "emulated single-request FIFO" fast-path in dummy_queue() reuses for small IN transfers: it copies the caller's request into it (req->req = *_req) and queues it, treating list_empty(&fifo_req.queue) as "the slot is free". The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(&req->queue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req->complete(). But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req->req = *_req -- overwriting req->complete while dummy_timer is mid-calling it. The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca). The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it. Add a fifo_req_busy bit covering the shared request's whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(&fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-request giveback sites. The shared slot can no longer be reused until its completion callback has finished.
Quoted source text, attributed separately from HOL analysis.