SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63874

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of USB communications within the MCTP (Management Component Transport Protocol) subsystem, specifically related to a race condition between stopping operations and retry work cancellation. This flaw can lead to unexpected behavior, potentially allowing queued USB requests to be re-scheduled even after a stop command is issued, which may compromise system stability or data integrity. Organizations using affected Linux distributions should prioritize patching this vulnerability to mitigate risks associated with USB device interactions.

CVE
CVE-2026-63874
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: mctp: usb: fix race between urb completion and rx_retry cancellation It's possible that sequencing between setting ->stopped and cancelling the rx_retry work (in ndo_stop) could leave us with an urb queued: T1: ndo_stop T2: rx_retry_work ------------ ---------------- LD: ->stopped => false ST: ->stopped <= true usb_kill_urb() mctp_usb_rx_queue() usb_submit_urb() cancel_delayed_work_sync() That urb completion can then re-schedule rx_retry_work. Strenghen the sequencing between the stop (preventing another requeue) and the cancel by updating both atomically under a new rx lock. After setting ->rx_stopped, and cancelling pending work, we know that the requeue cannot occur, so all that's left is killing any pending urb.