PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90030 Linux CVE debrief

A vulnerability in the Linux kernel's USB DWC3 driver has been resolved. The issue involves the forceRM bit in the DEPCMD register, which controls the EndTransfer command behavior. Setting forceRM=1 on certain DWC_usb31 controllers caused transfers to remain active after EndTransfer completion, leading to potential SMMU faults. The fix is to clear forceRM when issuing EndTransfer, aligning with newer programming guide recommendations.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-10-03
Advisory published
2026-09-16
Advisory updated
2026-10-03

Who should care

Defenders responsible for Linux kernel-based systems, particularly those using DWC_usb31 v2.00a and v2.10a controllers, should assess exposure and apply patches. Operators of affected systems must prioritize patching to prevent potential SMMU faults and data integrity risks. Vulnerability management and security teams should review DWC_usb31 controller configurations and verify patch application. Platform administrators should ensure that relevant security

Why it matters

Defenders should prioritize patching Linux kernel versions affected by CVE-2026-90030, particularly those using DWC_usb31 v2.00a and v2.10a controllers, to prevent potential SMMU faults and data integrity risks.

  • Potential SMMU faults due to lingering transfers
  • Data integrity risks if transfers are not properly terminated
  • Verification priority for Linux kernel versions and DWC_usb31 controller configurations
  • Patching and configuration changes required to mitigate vulnerability

Technical summary

The Linux kernel's USB DWC3 driver had a vulnerability where setting forceRM=1 on certain controllers could cause transfers to remain active after EndTransfer completion. This has been fixed by clearing forceRM when issuing EndTransfer. The fix aligns with newer programming guide recommendations and resolves potential SMMU faults and data integrity risks associated with lingering transfers on DWC_usb31 v2.00a and v2.10a controllers. Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly those using DWC_usb31 v2.00a and v2.10a controllers, to prevent potential issues.

Defensive priority

Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly those using DWC_usb31 v2.00a and v2.10a controllers.

Recommended defensive actions

  • Verify and apply Linux kernel patches for CVE-2026-90030
  • Review DWC_usb31 controller configurations for forceRM settings
  • Monitor for potential SMMU faults on affected systems
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source references provide details on the vulnerability and its resolution. However, specific affected Linux kernel versions and comprehensive testing results are not provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90030 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90030

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90030 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90030

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0afe5c31612de3d18cc6d16e616da4a48ba1e5a2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9f1e57c484f9edeaaa5a27a03ed985e98496e81d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b58e6200450d350314db0ecda7d6d1bde3281e80

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e01408ee52fe5cb2d0b43f47f359336af2b6c316

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.