{"id":"CVE-2026-10668","summary":"Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver","details":"The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base-\u003eCEPTXCNT = len in numaker_hsusbd_ep_trigger). Because the HSUSBD hardware cannot disarm a control Data IN already armed for a previous transfer, a USB host that cancels an in-flight control transfer (timeout) and then issues a new SETUP packet can drive the driver out of sync: stale data may be transmitted in the new transfer and the control endpoint can become permanently stuck NAK'ing every subsequent control transfer.\n\nA malicious or buggy host (physical/adjacent attacker driving the bus) can repeatedly cancel-and-re-SETUP to wedge the device's USB control endpoint, denying service to the device's USB function (the device stops enumerating/responding on the control pipe) until a USB reset or re-plug. The flaw is an availability-only denial of service; the FIFO copy loops (bounded by net_buf length and the hardware BUFFULL flag) and the net_buf lifecycle are independent of the arming desync, so there is no out-of-bounds access, use-after-free, or information leak.\n\nThe fix monitors the IN-token and new-SETUP events (k_event) and only arms control Data IN when an IN token is present and no new SETUP has arrived, cancelling the current transfer on a new SETUP. Affects boards using the Nuvoton NuMaker HSUSBD controller (CONFIG_UDC_NUMAKER with DT_HAS_NUVOTON_NUMAKER_HSUSBD_ENABLED); shipped in v4.4.0.","aliases":["GHSA-rm28-x84j-4qrx"],"modified":"2026-07-22T03:15:30.284700Z","published":"2026-07-12T16:16:51.243Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10668.json","unresolved_ranges":[{"extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.5.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10668.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-rm28-x84j-4qrx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10668"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"0"},{"fixed":"48e003326873e8bbc0ee4b67334e0dd8b5fb890f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0","v4.3.0-rc3","v4.3.0-rc2","v4.3.0-rc1","v4.2.0","v4.2.0-rc3","v4.2.0-rc2","v4.2.0-rc1","v4.1.0","v4.1.0-rc3","v4.1.0-rc2","v4.1.0-rc1","v4.0.0","v4.0.0-rc3","v4.0.0-rc2","v4.0.0-rc1","v3.7.0","v3.7.0-rc3","v3.7.0-rc2","v3.7.0-rc1","v3.6.0","v3.6.0-rc3","v3.6.0-rc2","v3.6.0-rc1","zephyr-v3.5.0","v3.5.0","v3.5.0-rc3","v3.5.0-rc2","v3.5.0-rc1","zephyr-v3.4.0","v3.4.0","v3.4.0-rc3","v3.4.0-rc2","v3.4.0-rc1","zephyr-v3.3.0","v3.3.0","v3.3.0-rc3","v3.3.0-rc2","v3.3.0-rc1","zephyr-v3.2.0","v3.2.0","v3.2.0-rc3","v3.2.0-rc2","v3.2.0-rc1","zephyr-v3.1.0","v3.1.0","v3.1.0-rc3","v3.1.0-rc2","v3.1.0-rc1","zephyr-v3.0.0","v3.0.0","v3.0.0-rc3","v3.0.0-rc2","v3.0.0-rc1","v2.7.99","v2.7.0-rc3","v2.7.0-rc2","v2.7.0-rc1","zephyr-v2.6.0","v2.6.0","v2.6.0-rc3","v2.6.0-rc2","v2.6.0-rc1","zephyr-v2.5.0","v2.5.0","v2.5.0-rc4","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","zephyr-v2.4.0","v2.4.0","v2.4.0-rc3","v2.4.0-rc2","v2.4.0-rc1","zephyr-v2.3.0","v2.3.0","v2.3.0-rc2","v2.3.0-rc1","zephyr-v2.1.0","v2.1.0","zephyr-v2.2.0","v2.2.0","v2.2.0-rc3","v2.2.0-rc2","v2.2.0-rc1","v2.1.0-rc3","v2.1.0-rc2","v2.1.0-rc1","zephyr-v2.0.0","v2.0.0","v2.0.0-rc3","v2.0.0-rc2","v2.0.0-rc1","zephyr-v1.14.0","v1.14.0","v1.14.0-rc3","v1.14.0-rc2","v1.14.0-rc1","zephyr-v1.13.0","v1.13.0","v1.13.0-rc3","v1.13.0-rc2","v1.13.0-rc1","zephyr-v1.12.0","v1.12.0","v1.12.0-rc3","v1.12.0-rc2","v1.12.0-rc1","zephyr-v1.11.0","v1.11.0","v1.11.0-rc3","v1.11.0-rc2","v1.11.0-rc1","zephyr-v1.10.0","v1.10.0","v1.10.0-rc3","v1.10.0-rc2","v1.10.0-rc1","zephyr-v1.9.0","v1.9.0","v1.9.0-rc4","v1.9.0-rc3","v1.9.0-rc2","v1.9.0-rc1","v1.8.99","zephyr-v1.5.0","v1.5.0","v1.7.99","v1.6.99","v1.5.0-rc4","v1.5.0-rc3","v1.5.0-rc2","v1.5.0-rc1","v1.5.0-rc0","zephyr-v1.4.0","v1.4.0","v1.4.0-rc3","v1.4.0-rc2","v1.4.0-rc1","zephyr-v1.3.0","v1.3.0","v1.3.0-rc2","v1.3.0-rc1","zephyr-v1.2.0","v1.2.0","v1.2.0-rc2","v1.2.0-rc1","zephyr-v1.1.0","v1.1.0","v1.1.0-rc1","zephyr-v1.0.0","v1.0.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"294802644622432222452728181771543973167","length":417},"id":"CVE-2026-10668-01649bdf","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f","target":{"file":"drivers/usb/udc/udc_numaker.c","function":"numaker_usbd_setup_th"}},{"target":{"file":"drivers/usb/udc/udc_numaker.c","function":"numaker_usbd_ep_th"},"deprecated":false,"digest":{"function_hash":"199899498820452951872873387320316611133","length":881},"id":"CVE-2026-10668-18dc4cc9","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f"},{"deprecated":false,"digest":{"function_hash":"212239203639149397585444336114230354849","length":988},"id":"CVE-2026-10668-35e18c17","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f","target":{"file":"drivers/usb/udc/udc_numaker.c","function":"numaker_hsusbd_cep_th"}},{"target":{"file":"drivers/usb/udc/udc_numaker.c","function":"numaker_usbd_msg_handle_setup"},"deprecated":false,"digest":{"function_hash":"200302612166562255512535830461200523904","length":1059},"id":"CVE-2026-10668-5aadf54b","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f"},{"deprecated":false,"digest":{"function_hash":"259217130851666443345745807267609963692","length":1247},"id":"CVE-2026-10668-b71aa87a","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f","target":{"file":"drivers/usb/udc/udc_numaker.c","function":"numaker_hsusbd_ep_trigger"}},{"id":"CVE-2026-10668-c961525b","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f","target":{"file":"drivers/usb/udc/udc_numaker.c","function":"udc_numaker_driver_preinit"},"deprecated":false,"digest":{"function_hash":"209744177636148665427396135275240675048","length":1955}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f","target":{"file":"drivers/usb/udc/udc_numaker.c"},"deprecated":false,"digest":{"line_hashes":["241389319298828758155412359237575490051","267055904774983317349638728921346387007","40138118548230778008255266612941667642","275046065276559897256636072759879234282","32530242017450250541540051939140552967","255380828010655616339518745637221977379","100492035784340582716280462175624235590","114285645307682133736964390271327749067","109317845498026655607785193763121894604","104988587042474614407231295697768313182","225871503410594470815271421288829065707","11669908138967421139441558434838288220","328974649846732901683815576787432944827","307577814714316669172416844609646604764","338215714557520052180863809928365858225","226925310355881346695537275873931970122","164478775703085564434164384213117022061","138263951981620687572486744864866758439","175697311187174933202758335604804890097","93237164439815077592996162089381459882","71392853754803693621778314366652141811","64304858125680409711860857753408069677","187893672326624475372276793853607560312","125901265339356648589673505474386623907","6491507777104203554669675076412710217","185167210619691597433800290998027245749","173925807139309266035499105364069310157","276202176694071034195555892590857491727","176184562291609012968977574243477787223","207865259613439440994404301686130648875","145913377304301723931421822172469869901","189457131755699308990406145829866357216","115815126631472291737657172055085405327","258879464636268114514269906129079757646","236782500404038691611201929168572570803","169518978909707772120578658196004662577","338215714557520052180863809928365858225","38374748597581438494344525832808826267","239961554600311872959603801992881262200","8652640204482289202764827715566003162","284030959744367045918304269475110674105","81436964055058554113419113157641829042","266037353660085666874869413416003724426","172225370413054222648542128688239257973","185705523847884662306044097758801483813","329735100072484430486884419840467291800","85751920025150946971692036704924096403","272977260060252353713746571484769882557","64400482636567351965778678002229580463","156758402341057987987580195257074515486","40176666044894879608797774476589546686","273643278986455083148215799693680925472","246859851977276712200208529344209379762"],"threshold":0.9},"id":"CVE-2026-10668-cecf480b"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10668.json","vanir_signatures_modified":"2026-07-22T03:15:30Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}