HomeDefectsLIN1024-21101
Acknowledged

LIN1024-21101 : Security Advisory - linux - CVE-2026-31755

Created: May 12, 2026    Updated: May 14, 2026
Found In Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  usb: cdns3: gadget: fix NULL pointer dereference in ep_queue  When the gadget endpoint is disabled or not yet configured, the ep->desc pointer can be NULL. This leads to a NULL pointer dereference when __cdns3_gadget_ep_queue() is called, causing a kernel crash.  Add a check to return -ESHUTDOWN if ep->desc is NULL, which is the standard return code for unconfigured endpoints.  This prevents potential crashes when ep_queue is called on endpoints that are not ready.