Operation on a Resource after Expiration or Release in Linux kernel - CVE-2026-90030
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource lifetime management in DWC3 EndTransfer handling when aborting a transfer through the ep_dequeue path and subsequently starting a transfer on the same endpoint. A local user can trigger this transfer sequence to cause a denial of service.
The observed condition affects DWC_usb31 v2.00a and v2.10a controllers.