A AegiFlow
HIGHCVSS 7.8

CVE-2026-63874

CVE-2026-63874 updated by NVD

Modified
2026-07-29
Sources
nvd

Summary

In the Linux kernel, the following vulnerability has been resolved: net: mctp: usb: fix race between urb completion and rx_retry cancellation It's possible that sequencing between setting ->stopped and cancelling the rx_retry work (in ndo_stop) could leave us with an urb queued: T1: ndo_stop T2: rx_retry_work ------------ ---------------- LD: ->stopped => false ST: ->stopped rx_stopped, and cancelling pending work, we know that the requeue cannot occur, so all that's left is killing any pending urb.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.