CVE-2026-31615
Published: Apr 24, 2026
Modified: Jun 1, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: renesas_usb3: validate endpoint index in standard request handlers The GET_STATUS and SET/CLEAR_FEATURE handlers extract the endpoint number from the host-supplied wIndex without any sort of validation. Fix this up by validating the number of endpoints actually match up with the number the device has before attempting to dereference a pointer based on this math. This is just like what was done in commit ee0d382feb44 ("usb: gadget: aspeed_udc: validate endpoint index for ast udc") for the aspeed driver.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 746bfe63bba37ad55956b7377c9af494e7e28929 - < 7caaf76207f50c77abfd788380e19b2c23a94415affected 746bfe63bba37ad55956b7377c9af494e7e28929 - < c4e5ae6db2328d2d9ed55d3005a36c13faab0752affected 746bfe63bba37ad55956b7377c9af494e7e28929 - < 360aa6e71870a175a6d86af905be2ca171639eb3affected 746bfe63bba37ad55956b7377c9af494e7e28929 - < 1b2bfedccc4fb8c9572e1ea464f905424c91de2aaffected 746bfe63bba37ad55956b7377c9af494e7e28929 - < adb8014599fdf0818d3d93f1f74e06cd0bdec08d+4 more versions |
Linux | Linux | affected 4.5unaffected 0 - < 4.5unaffected 5.10.258 - <= 5.10.*unaffected 5.15.209 - <= 5.15.*unaffected 6.1.175 - <= 6.1.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now