CVE-2026-97483
Last modified
CVE-2026-97483 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: core: hcd: fix possible deadlock in rh control transfers >From within the SCSI error handler memory allocations must not trigger IO. Handling errors in UAS and the storage driver may involve resetting a device.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: core: hcd: fix possible deadlock in rh control transfers >From within the SCSI error handler memory allocations must not trigger IO. Handling errors in UAS and the storage driver may involve resetting a device. The thread doing the reset itself relies on VM magic. However, that is insufficient, as resetting a device involves resuming it. Resumption as well as resetting involves conrol transfers to the parent of the device to be reset. That may be a root hub. Hence usbcore must heed the flags passed to usb_submit_urb() processing control transfers to root hubs. The problem exist since the storage driver has been merged.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < fff917c85d37a294397c5440a795591ca9d6b602; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 549672a3fb6b36ea408238f89ecf9f41d2da6225; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < d5559f43d76b398392b26a15cbc16d731969cd1c; < 6.12.111; < 6.18.53 |
| Linux | Linux | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-97483?
How severe is CVE-2026-97483?
How do I fix CVE-2026-97483?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97478In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-97479In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9748The $_internalConvertBucketIndexStats stage used PauseExecut…7.1
- CVE-2026-97480In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97481In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97482In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97484In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97485In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97486In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97487In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97488In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97489In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-97483?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
