Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-97430

 

Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-97430

Published: September 25, 2026


Vulnerability identifier: #VU152209
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97430
CWE-ID: CWE-754
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to queue new commands on the command ring while the xHC is inaccessible.

The vulnerability exists due to an improper check for an inaccessible hardware state in the xHCI command-ring queueing logic when the controller is suspended or resumed. A local user can initiate command queueing while the xHC is inaccessible to queue new commands on the command ring.


Affected software

Linux kernel

How to mitigate CVE-2026-97430

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins