SB20260925230 - Improper Check for Unusual or Exceptional Conditions in Linux kernel usb host driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-97430)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to queue new commands on the command ring while the xHC is inaccessible.
The vulnerability exists due to an improper check for an inaccessible hardware state in the xHCI command-ring queueing logic when the controller is suspended or resumed. A local user can initiate command queueing while the xHC is inaccessible to queue new commands on the command ring.
Remediation
Install update from vendor's website.