CVE-2026-64583
Last modified
CVE-2026-64583 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only after bdc_remove() returns. devm releases resources in reverse LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -> bdc_mem_free() manually before returning: bdc_udc_exit() tears down individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -> bdc_mem_free() frees and NULLs the DMA-coherent status-report ring (bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only after bdc_remove() returns. devm releases resources in reverse LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -> bdc_mem_free() manually before returning: bdc_udc_exit() tears down individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -> bdc_mem_free() frees and NULLs the DMA-coherent status-report ring (bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. Both happen while the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED) remains deliverable in the window up to the post-remove devm free_irq(). On receipt of a shared interrupt in that window, bdc_udc_interrupt() dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA) and dispatches sr_handler callbacks that index into bdc_ep_array, causing a NULL-deref or use-after-free. The same window affects the delayed_work bdc->func_wake_notify, which is armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change() -> schedule_delayed_work() and may self-rearm from its own callback bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a queued work item that fires after bdc_remove() returns and the bdc structure is devm-freed dereferences freed memory. Replace devm_request_irq() with request_irq() and add an explicit free_irq(bdc->irq, bdc) in bdc_remove(). Clear BDC_GIE before free_irq() to stop the device from asserting interrupts, then free_irq() drains any in-flight handler, then cancel_delayed_work_sync() drains the func_wake_notify delayed work. This ordering ensures the IRQ handler and delayed work cannot interfere with the subsequent endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the matching free_irq() into the bdc_udc_init() error path so the IRQ is released on probe failure, and route the bdc_init_ep() failure through err0 instead of returning directly. This issue was found by an in-house static analysis tool.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= efed421a94e62a7ddbc76acba4312b70e4be958f, < 1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8; >= efed421a94e62a7ddbc76acba4312b70e4be958f, < f6fc21ec7ccd83726ba766d73d0b8cc03e726475; >= efed421a94e62a7ddbc76acba4312b70e4be958f, < dcf3e2f164435b5844706cb8eefef29ebee0eedb; >= efed421a94e62a7ddbc76acba4312b70e4be958f, < d4964a74717107697999f48bcb4e80a9c0679a27; >= efed421a94e62a7ddbc76acba4312b70e4be958f, < 0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb |
| Linux | Linux | 3.19 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-64583?
How severe is CVE-2026-64583?
How do I fix CVE-2026-64583?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64578In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2026-64579In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6458Missing cryptographic step in Caliptra Core Firmware (aes_25…5.1
- CVE-2026-64580In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64581In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64582In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64584In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64585In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64586In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-64587In the Linux kernel, the following vulnerability has been re…7
- CVE-2026-64588In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64589In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64583?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
