CVE-2026-97484

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/09/2026
Last modified:
24/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usbip: vhci_hcd: fix NULL deref in status_show_vhci<br /> <br /> platform_get_drvdata() can return NULL if a VHCI host controller&amp;#39;s<br /> probe failed (e.g. due to USB bus number exhaustion). status_show_vhci()<br /> checked for a NULL pdev but not for a NULL hcd returned by<br /> platform_get_drvdata(). Passing NULL to hcd_to_vhci_hcd() does not<br /> return NULL - it returns a pointer offset of 0x260, causing a NULL<br /> pointer dereference when that value is subsequently dereferenced.<br /> <br /> Add a NULL check on hcd before calling hcd_to_vhci_hcd(). Move<br /> status_show_not_ready() above status_show_vhci() to make it callable<br /> from the new error path without a forward declaration.

Impact