SB20260727219 - Memory leak in Linux kernel usb cdns3 driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-64350)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in cdnsp_alloc_stream_info() when handling stream ring allocation or stream mapping update failures. A local user can trigger allocation failure conditions to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3348f444a4ce43dd5c2d1aa41634cb6eff33aa64
- https://git.kernel.org/stable/c/37283f5a47127fbdea567749a2110766af53d18d
- https://git.kernel.org/stable/c/963075c4da0cd43b3d17b107c355e1eb0ee64a58
- https://git.kernel.org/stable/c/c00826e87bb75e14e0381b05da5f18ffd0241ab6
- https://git.kernel.org/stable/c/cb8e9391b7f4f77d112c51910cd7c355a337ef76
- https://git.kernel.org/stable/c/d9643bbe93a6aee24edee1a86e0303aa74bcd320
- https://git.kernel.org/stable/c/fde3c095e1d48e0ac3ab8bc32905da42fe58a36a