๐Ÿ” CVE Alert

CVE-2026-64346

UNKNOWN 0.0

usb: gadget: udc: Fix use-after-free in gadget_match_driver

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: Fix use-after-free in gadget_match_driver The udc structure acts as the management structure for the gadget, but their lifecycles are decoupled. A race condition exists where usb_del_gadget() frees the udc memory (e.g., via mode-switch work) while gadget_match_driver() concurrently accesses the freed udc memory (e.g., via configfs), causing a Use-After-Free (UAF) that triggers a NULL pointer dereference when the freed memory is zeroed: [39430.908615][ T1171] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [39430.911397][ T1171] pc : __pi_strcmp+0x20/0x140 [39430.911441][ T1171] lr : gadget_match_driver+0x34/0x60 ... [39430.911890][ T1171] usb_gadget_register_driver_owner+0x50/0xf8 [39430.911910][ T1171] gadget_dev_desc_UDC_store+0xf4/0x140 [39430.931308][ T1171] configfs_write_iter+0xec/0x134 [39430.957058][ T1171] Workqueue: events_freezable __dwc3_set_mode [39430.957287][ T1171] dwc3_gadget_exit+0x34/0x8c [39430.957304][ T1171] __dwc3_set_mode+0xc0/0x664 Fix this by ensuring the udc structure remains allocated until the gadget is released. To achieve this, introduce a new usb_gadget_release() routine to the core. When the gadget is added, usb_add_gadget() stores the gadget's release routine in the udc structure and takes a reference to the udc. When the gadget is released, usb_gadget_release() drops the reference to the udc and then calls the gadget's release routine.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f845852a5a8914277031f47d8de0f350fef52405 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 50eeb8e8a4f389efc91b93cff14a683e714ec194 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7a5214dae906d9f58e07bc4995e8181ee74439f4 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d026f71df141c9b064ff32a78af5391a31ef75c2 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b52476a83d9e12df00765359d728a875b128bef1 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 54fa390aae393eb130f307a85562e3001cc39a52 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea 0 < 5.15.212 0 < 6.1.178 0 < 6.6.145 0 < 6.12.96 0 < 6.18.39 0 < 7.1.4
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f845852a5a8914277031f47d8de0f350fef52405 git.kernel.org: https://git.kernel.org/stable/c/50eeb8e8a4f389efc91b93cff14a683e714ec194 git.kernel.org: https://git.kernel.org/stable/c/7a5214dae906d9f58e07bc4995e8181ee74439f4 git.kernel.org: https://git.kernel.org/stable/c/d026f71df141c9b064ff32a78af5391a31ef75c2 git.kernel.org: https://git.kernel.org/stable/c/b52476a83d9e12df00765359d728a875b128bef1 git.kernel.org: https://git.kernel.org/stable/c/54fa390aae393eb130f307a85562e3001cc39a52 git.kernel.org: https://git.kernel.org/stable/c/67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea