Medium severity5.5NVD Advisory· Published Jul 25, 2026· Updated Sep 3, 2026
CVE-2026-64350
CVE-2026-64350
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
cdnsp_alloc_stream_info() allocates stream_info->stream_ctx_array with cdnsp_alloc_stream_ctx(). If a later stream ring allocation or stream mapping update fails, the error path frees the allocated stream rings and stream_rings array, but leaves stream_ctx_array allocated.
Free the stream context array before falling through to the stream_rings cleanup path.
Affected products
3- osv-coords2 versions
< 7.1.7-1.1+ 1 more
- (no CPE)range: < 7.1.7-1.1
- (no CPE)range: >= 5.12.0, < 5.15.212
Patches
Vulnerability mechanics
References
7- git.kernel.org/stable/c/3348f444a4ce43dd5c2d1aa41634cb6eff33aa64nvdPatch
- git.kernel.org/stable/c/37283f5a47127fbdea567749a2110766af53d18dnvdPatch
- git.kernel.org/stable/c/963075c4da0cd43b3d17b107c355e1eb0ee64a58nvdPatch
- git.kernel.org/stable/c/c00826e87bb75e14e0381b05da5f18ffd0241ab6nvdPatch
- git.kernel.org/stable/c/cb8e9391b7f4f77d112c51910cd7c355a337ef76nvdPatch
- git.kernel.org/stable/c/d9643bbe93a6aee24edee1a86e0303aa74bcd320nvdPatch
- git.kernel.org/stable/c/fde3c095e1d48e0ac3ab8bc32905da42fe58a36anvdPatch
News mentions
0No linked articles in our index yet.