๐Ÿ” CVE Alert

CVE-2026-68374

HIGH 7.8

usb: core: sysfs: add lock to bos_descriptors_read()

CVSS Score
7.8
EPSS Score
0.1%
EPSS Percentile
3th

In the Linux kernel, the following vulnerability has been resolved: usb: core: sysfs: add lock to bos_descriptors_read() Add a lock to the function bos_descriptors_read(). This function accesses udev->bos, which could be simultaneously freed in usb_reset_and_verify_device(), a function that is commonly called in drivers all over the kernel.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
12fc84e8c4288cc8ed5f14a35e077130c2cfece2 < c07caee449c968842a350bfefa049889923b8240 12fc84e8c4288cc8ed5f14a35e077130c2cfece2 < 217774e143d7b5a88739193284b6421be3978601 12fc84e8c4288cc8ed5f14a35e077130c2cfece2 < ab82adf5e63b2d89ead7933ab753b9cedbe028e9 12fc84e8c4288cc8ed5f14a35e077130c2cfece2 < 4e0197fbb0eec588795d5431716a244d9ac8fa93
Linux / Linux
6.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c07caee449c968842a350bfefa049889923b8240 git.kernel.org: https://git.kernel.org/stable/c/217774e143d7b5a88739193284b6421be3978601 git.kernel.org: https://git.kernel.org/stable/c/ab82adf5e63b2d89ead7933ab753b9cedbe028e9 git.kernel.org: https://git.kernel.org/stable/c/4e0197fbb0eec588795d5431716a244d9ac8fa93