Back to overview

CVE-2026-64350

Description
In the Linux kernel, the following vulnerability has been resolved: usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() cdnsp_alloc_stream_info() allocates stream_info->stream_ctx_array with cdnsp_alloc_stream_ctx(). If a later stream ring allocation or stream mapping update fails, the error path frees the allocated stream rings and stream_rings array, but leaves stream_ctx_array allocated. Free the stream context array before falling through to the stream_rings cleanup path.

Metadata

CVE ID
CVE-2026-64350
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:50 UTC
Last updated
2026-07-25 08:50 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux — 3d82904559f4f5a2622db1b21de3edf2eded7664 < 37283f5a47127fbdea567749a2110766af53d18d, 3d82904559f4f5a2622db1b21de3edf2eded7664 < cb8e9391b7f4f77d112c51910cd7c355a337ef76, 3d82904559f4f5a2622db1b21de3edf2eded7664 < fde3c095e1d48e0ac3ab8bc32905da42fe58a36a, 3d82904559f4f5a2622db1b21de3edf2eded7664 < d9643bbe93a6aee24edee1a86e0303aa74bcd320 …
Linux Linux — 5.12, 0 < 5.12, 5.15.212 ≤ 5.15.*, 6.1.178 ≤ 6.1.* …
Back to overview