SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80826

UNKNOWN · CVSS N/A EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the USB subsystem, specifically in the c67x00 driver, where a use-after-free condition can occur during the handling of isochronous URBs. This flaw can lead to potential memory corruption, allowing attackers to exploit freed memory, which may result in system instability or arbitrary code execution. Organizations using affected Linux systems, particularly those relying on USB devices managed by the c67x00 driver, should prioritize applying the patch to mitigate these risks.

CVE
CVE-2026-80826
Severity
UNKNOWN
CVSS
N/A
EPSS
0.19%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: USB: c67x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state. c67x00_giveback_urb() frees the URB private data, and the completion callback may release the final URB reference. The following accesses to urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed memory. Update next_frame and cnt before giving back the failed final packet, making the giveback the last operation that uses the URB and its private data.