CVE-2026-64342

UnknownEPSS 0.18%

Last modified

CVE-2026-64342 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: USB: iowarrior: fix use-after-free on disconnect Submitted write URBs are not stopped on close() and therefore need to be stopped unconditionally on disconnect() to avoid use-after-free in the completion handler.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: USB: iowarrior: fix use-after-free on disconnect Submitted write URBs are not stopped on close() and therefore need to be stopped unconditionally on disconnect() to avoid use-after-free in the completion handler.

Metrics

EPSS Probability
0.18%

7.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 946b960d13c15f050a3b848987aaca79f6a459b7, < d058d377291567b72aea33b017215cbfb383b0ad; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < a7bbe946ca3a6eeb6f364d5e84b05e02c7c0d595; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < 97ad9337127be04ca0b027c2b01e69302353f404; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < 164398601a7f160bc3df1efa454f983302cef03f; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < f328b0e9a0dbd162f5db1b83026b689f2fea2241; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < b748f97aff339e7f08dca9cf38a05b980fb66fea; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < e4596816984efc537e7c04c1af0c639394f967f7; >= 946b960d13c15f050a3b848987aaca79f6a459b7, < bc0e4f16c44e50daa0b1ea729934baa3b4815dee
LinuxLinux2.6.21

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-64342?
In the Linux kernel, the following vulnerability has been resolved: USB: iowarrior: fix use-after-free on disconnect Submitted write URBs are not stopped on close() and therefore need to be stopped unconditionally on disconnect() to avoid use-after-free in the completion handler.
How severe is CVE-2026-64342?
Severity scoring for CVE-2026-64342 is pending analysis. The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-64342?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64342?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST