CVE-2026-64349 | Linux Kernel up to 6.18.39/7.1.3/7.2-rc2 dwc3 drivers/usb/dwc3/core.c dwc3_ulpi_setup regs initialization
A vulnerability was found in Linux Kernel up to 6.18.39/7.1.3/7.2-rc2. It has been rated as very critical. This issue affects the function dwc3_ulpi_setup of the file drivers/usb/dwc3/core.c of the component dwc3. Performing a manipulation of the argument regs results in improper initialization.
This vulnerability is known as CVE-2026-64349. Attacking locally is a requirement. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More