ThreatCluster

Multiple CVEs Affecting Renesas USB Host Controller

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 52

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been reported in the Renesas USB Host Controller. CVE-2025-21917, published on April 1, 2025, addresses issues with flushing the notify_hotplug_work, while CVE-2025-38136, published on July 3, 2025, involves reordering clock handling and power management during the probe process. Affected systems may experience instability or performance issues due to these vulnerabilities.

Timeline

2025-04-01
CVE-2025-21917 published
2025-07-03
CVE-2025-38136 published
2026-02-18
Articles published detailing both CVEs