A vulnerability has been found in Linux Kernel up to 7.2-rc2 and classified as critical. This affects the function vep_dequeue of the component usbip. Performing a manipulation of the argument udc results in null pointer dereference.

This vulnerability is reported as CVE-2026-64331. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.