---
id: CVE-2026-97484
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  usbip: vhci_hcd: fix NULL deref in status_show_vhci

  platform_get_drvdata() can return NULL if a VHCI host controller's
  probe failed (e.g
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  usbip: vhci_hcd: fix NULL deref in status_show_vhci

  platform_get_drvdata() can return NULL if a VHCI host controller's
  probe failed (e.g. due to USB bus number exhaust…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    046a94fdb02eb1df86c8fa4614104ff801ba3ab7
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    dacd7c317ba12e035653c28a0eaaf23d91abc073
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    bc150783542ba2e7c1257d1299c6f3269bdba270
  - Linux < 6.12.111
  - Linux < 6.18.53
  - Linux (all versions)
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T17:17:25.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97484'
references:
  - url: 'https://git.kernel.org/stable/c/046a94fdb02eb1df86c8fa4614104ff801ba3ab7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc150783542ba2e7c1257d1299c6f3269bdba270'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dacd7c317ba12e035653c28a0eaaf23d91abc073'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T16:47:15.869Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

usbip: vhci_hcd: fix NULL deref in status_show_vhci

platform_get_drvdata() can return NULL if a VHCI host controller's
probe failed (e.g. due to USB bus number exhaustion). status_show_vhci()
checked for a NULL pdev but not for a NULL hcd returned by
platform_get_drvdata(). Passing NULL to hcd_to_vhci_hcd() does not
return NULL - it returns a pointer offset of 0x260, causing a NULL
pointer dereference when that value is subsequently dereferenced.

Add a NULL check on hcd before calling hcd_to_vhci_hcd(). Move
status_show_not_ready() above status_show_vhci() to make it callable
from the new error path without a forward declaration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
