Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-64337

In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: unmap request DMA on queue failure mtu3_gadget_queue() maps the request before checking whether the QMU GPD ring can accept another transfer. the request is returned with -EAGAIN before it is linked on the endpoint request list if mtu3_prepare_transfer() fails. Normal completion and dequeue paths unmap requests from mtu3_req_complete(), but this error path never reaches that helper, so the DMA mapping is left active. Unmap the request before returning from the failed queue path.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 11.9%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2026-64337


Contact Us

Shodan ® - All rights reserved