Medium severity5.5NVD Advisory· Published Jul 25, 2026· Updated Sep 4, 2026
CVE-2026-64327
CVE-2026-64327
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
When parsing endpoint descriptors, ffs_data_got_descs() generates the eps_addrmap which contains the endpoint direction. However, epfile->in was previously only populated in ffs_func_eps_enable() which executes upon USB host connection. As a result, early userspace ioctls like FUNCTIONFS_DMABUF_ATTACH that run before the host connects would see epfile->in as 0, leading to incorrect DMA directions.
By moving the initialization to ffs_epfiles_create(), epfile->in is accurate before userspace opens the endpoint files.
Affected products
3- osv-coords2 versions
>= 6.9.0, < 6.12.96+ 1 more
- (no CPE)range: >= 6.9.0, < 6.12.96
- (no CPE)range: < 7.1.7-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.