CVE-2026-31754
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2026
Last modified:
08/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: cdns3: gadget: fix state inconsistency on gadget init failure<br />
<br />
When cdns3_gadget_start() fails, the DRD hardware is left in gadget mode<br />
while software state remains INACTIVE, creating hardware/software state<br />
inconsistency.<br />
<br />
When switching to host mode via sysfs:<br />
echo host > /sys/class/usb_role/13180000.usb-role-switch/role<br />
<br />
The role state is not set to CDNS_ROLE_STATE_ACTIVE due to the error,<br />
so cdns_role_stop() skips cleanup because state is still INACTIVE.<br />
This violates the DRD controller design specification (Figure22),<br />
which requires returning to idle state before switching roles.<br />
<br />
This leads to a synchronous external abort in xhci_gen_setup() when<br />
setting up the host controller:<br />
<br />
[ 516.440698] configfs-gadget 13180000.usb: failed to start g1: -19<br />
[ 516.442035] cdns-usb3 13180000.usb: Failed to add gadget<br />
[ 516.443278] cdns-usb3 13180000.usb: set role 2 has failed<br />
...<br />
[ 1301.375722] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller<br />
[ 1301.377716] Internal error: synchronous external abort: 96000010 [#1] PREEMPT SMP<br />
[ 1301.382485] pc : xhci_gen_setup+0xa4/0x408<br />
[ 1301.393391] backtrace:<br />
...<br />
xhci_gen_setup+0xa4/0x408
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4 (including) | 5.15.203 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.168 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.134 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.81 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.22 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/5a85599ca4d2584d89dc69f4fc49303b75a42338
- https://git.kernel.org/stable/c/9b1d301fbae837bf6979a19030b81d869bb15f7a
- https://git.kernel.org/stable/c/b490f0e477d26d29ed51e5dc47e3b9bd31bcb49f
- https://git.kernel.org/stable/c/c32f8748d70c8fc77676ad92ed76cede17bf2c48
- https://git.kernel.org/stable/c/c7e475ae3a5593c5db21b3b7dca4ba8bdac9b47f
- https://git.kernel.org/stable/c/cfca84f5986afceb63a3adf39d4a98e915aebbc2
- https://git.kernel.org/stable/c/fb7110a052467098967284ef14d306810b354937



