CVE-2026-31615

Source
https://cve.org/CVERecord?id=CVE-2026-31615
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31615.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31615
Downstream
Related
Published
2026-04-24T14:42:34.806Z
Modified
2026-06-03T03:54:51.418037903Z
Summary
usb: gadget: renesas_usb3: validate endpoint index in standard request handlers
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: renesas_usb3: validate endpoint index in standard request handlers

The GETSTATUS and SET/CLEARFEATURE handlers extract the endpoint number from the host-supplied wIndex without any sort of validation. Fix this up by validating the number of endpoints actually match up with the number the device has before attempting to dereference a pointer based on this math.

This is just like what was done in commit ee0d382feb44 ("usb: gadget: aspeed_udc: validate endpoint index for ast udc") for the aspeed driver.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31615.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
746bfe63bba37ad55956b7377c9af494e7e28929
Fixed
7caaf76207f50c77abfd788380e19b2c23a94415
Fixed
c4e5ae6db2328d2d9ed55d3005a36c13faab0752
Fixed
360aa6e71870a175a6d86af905be2ca171639eb3
Fixed
1b2bfedccc4fb8c9572e1ea464f905424c91de2a
Fixed
adb8014599fdf0818d3d93f1f74e06cd0bdec08d
Fixed
44216e3dd4455b798899b50eedb0ec3831dff8e0
Fixed
37f430b2240655e6b0199a92aa1057e4d621be51
Fixed
e3d42598f2995cdc07b7779874e7c5f8a1b773db
Fixed
f880aac8a57ebd92abfa685d45424b2998ac1059

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31615.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.136
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.83
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.24
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.14
Type
ECOSYSTEM
Events
Introduced
6.20.0
Fixed
7.0.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31615.json"