๐Ÿ” CVE Alert

CVE-2026-89733

HIGH 7.8

usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() In uvc_function_bind() error path, we use usb_ep_free_request which uses uvc->control_req but does not set it to NULL afterwards. Thus, uvc->control_req is a dangling pointer causing a UAF. Also we do not set the uvc->control_buf pointer to NULL after freeing it, which is another dangling pointer. Fix it by setting uvc->control_req to NULL after we run usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the same for uvc_function_unbind().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
0f9df939385527049c8062a099fbfa1479fe7ce0 < ddb1b0d5d858584ed0d3a5aaa042ee693998c7e2 0f9df939385527049c8062a099fbfa1479fe7ce0 < 85dd5e8bd6776d02854f2847d83429f1f712e99c 0f9df939385527049c8062a099fbfa1479fe7ce0 < 502a7f5b79b7ba751988789e982924f8f496129f 0f9df939385527049c8062a099fbfa1479fe7ce0 < bec7708eb3b5295d12e931db24381b7c94c72953 0f9df939385527049c8062a099fbfa1479fe7ce0 < 8e88ed8a374de67270d38689f2a81018909cafbb 0f9df939385527049c8062a099fbfa1479fe7ce0 < 9897b7da8c0ad8356c1b8649379fcb5a689462cb 0f9df939385527049c8062a099fbfa1479fe7ce0 < 38f822ddce9355893d734279a26ddec45182197e 0f9df939385527049c8062a099fbfa1479fe7ce0 < bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc 1efa8a5aac93d9e67075995d7d4902b57ce184f7 e7a4b0efe62e56a0acc81d16091c6efc2a282be8 065f5561a20659cf17aae5f72b32b5c2695c8e00 3.2.36 < 3.3 3.4.25 < 3.5 3.7.2 < 3.8
Linux / Linux
3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ddb1b0d5d858584ed0d3a5aaa042ee693998c7e2 git.kernel.org: https://git.kernel.org/stable/c/85dd5e8bd6776d02854f2847d83429f1f712e99c git.kernel.org: https://git.kernel.org/stable/c/502a7f5b79b7ba751988789e982924f8f496129f git.kernel.org: https://git.kernel.org/stable/c/bec7708eb3b5295d12e931db24381b7c94c72953 git.kernel.org: https://git.kernel.org/stable/c/8e88ed8a374de67270d38689f2a81018909cafbb git.kernel.org: https://git.kernel.org/stable/c/9897b7da8c0ad8356c1b8649379fcb5a689462cb git.kernel.org: https://git.kernel.org/stable/c/38f822ddce9355893d734279a26ddec45182197e git.kernel.org: https://git.kernel.org/stable/c/bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc