← All Advisories

CVE-2026-97483

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97483

Key Details

CVECVE-2026-97483
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

usb: core: hcd: fix possible deadlock in rh control transfers

>From within the SCSI error handler memory allocations must not

trigger IO. Handling errors in UAS and the storage driver may

involve resetting a device. The thread doing the reset itself

relies on VM magic. However, that is insufficient, as resetting

a device involves resuming it. Resumption as well as resetting

involves conrol transfers to the parent of the device to be reset.

That may be a root hub. Hence usbcore must heed the flags passed

to usb_submit_urb() processing control transfers to root hubs.

The problem exist since the storage driver has been merged. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97483
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97483