CVE-2026-64332
In the Linux kernel, the following vulnerability has been resolved:
USB: ulpi: fix memory leak on registration failure
The allocated device name is never freed on early ULPI device
registration failures.
Fix this by initialising the device structure earlier and releasing the
initial reference whenever registration fails.
CSIRTS triage
- What
- This vulnerability involves a memory leak that occurs during USB registration failure.
- Who is affected
- Deployments using the affected USB subsystem.
- Urgency
- Remediation is necessary to prevent potential resource exhaustion, although exploitation is not currently reported.
- Action
- Apply the patch for CVE-2026-64332.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-64332
Get an email if CVE-2026-64332 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownCVE-2026-64332: In the Linux kernel, the following vulnerability has been resolved: USB: ulpi: fix memory leak…nvd · 2026-07-25
- mediumCVE-2026-64332: USB: ulpi: fix memory leak on registration failuremsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-64332)