CVE-2026-80826
N/AIn the Linux kernel, the following vulnerability has been resolved: USB: c67x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state. c67x00_giveback_urb() frees the URB private data, and the completion callback may release the final URB reference. The following accesses to urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed memory. Update next_frame and cnt before giving back the failed final packet, making the giveback the last operation that uses the URB and its private data.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
—EPSS not yet scored
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-80826/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-80826/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/e4039e9bebb528dd9cd7ac72aeaec529c26c355a
- https://git.kernel.org/stable/c/ade18b4ce78a16558f4f435aece80082f6f7b64c
- https://git.kernel.org/stable/c/bb572801290e25ec1c4753d14af35777303f5d6b
- https://git.kernel.org/stable/c/62cd519ab74cac499036cd88c11692f8f0d53e14
- https://git.kernel.org/stable/c/ff172092cba7ec990ecc7b610ce703e19570b8f0
- https://git.kernel.org/stable/c/b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421
- https://git.kernel.org/stable/c/7983daa159981fac125db2457437723f38ea1472
- https://git.kernel.org/stable/c/f24dcc61bd0ecf7639fac5bf700450b398d793a7
- https://git.kernel.org/stable/c/b1e24de475bf2d66fffc9103f3444b783527d55a