Back to overview

CVE-2026-64349

Description
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() The dwc3_ulpi_setup() calls the register read and write calls with dwc3->regs when both these calls take the dwc3 structure directly. Chnage these two calls to fix the following sparse warning, and possibly a nasty bug in the dwc3_ulpi_setup() code: drivers/usb/dwc3/core.c:796:45: warning: incorrect type in argument 1 (different address spaces) drivers/usb/dwc3/core.c:796:45: expected struct dwc3 *dwc drivers/usb/dwc3/core.c:796:45: got void [noderef] __iomem *regs drivers/usb/dwc3/core.c:798:40: warning: incorrect type in argument 1 (different address spaces) drivers/usb/dwc3/core.c:798:40: expected struct dwc3 *dwc drivers/usb/dwc3/core.c:798:40: got void [noderef] __iomem *regs

Metadata

CVE ID
CVE-2026-64349
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:50 UTC
Last updated
2026-07-25 08:50 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 476ee6389120e1900290b46081b3a12b54e05672 < 41a4e80d5af04855e68ac88f5e2cd07fa67287f8, 9accc68b1cf0a2b220f51d53641128bb32598070 < 4349e487a1149ff33b65d53427b8aca57f2e4578, 9accc68b1cf0a2b220f51d53641128bb32598070 < e0f844d9d74200d311c6438a0f04270834ba5365, 6.18.32 < 6.18.40
Linux Linux 7.0, 0 < 7.0, 6.18.40 ≤ 6.18.*, 7.1.4 ≤ 7.1.* …
Back to overview