๐Ÿ” CVE Alert

CVE-2026-90021

UNKNOWN 0.0

usb: gadget: f_midi: initialize work in f_midi_alloc()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi_register_card(). f_midi_register_card() is only called in f_midi_bind() which actually performs INIT_WORK. If f_midi_bind() is never run, work is not initialized and the if condition in f_midi_free becomes true, this results in a warning later in __flush_work as work->func = 0. Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 3d8b11255e632170f32f1925bfcaf96331f36317 8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 02ac76f27db23ef652358458c272d9d2d6f51167 8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 858576de6b2f5166b08dae803f0fd0766dcb3002 8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 7e07d3e4c389217d7d7171d80edf2e23ac70f1ea 89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d 3635523e9b96213969693c320302d536774d8e9b 5.4.291 < 5.5 5.10.235 < 5.11
Linux / Linux
5.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3d8b11255e632170f32f1925bfcaf96331f36317 git.kernel.org: https://git.kernel.org/stable/c/02ac76f27db23ef652358458c272d9d2d6f51167 git.kernel.org: https://git.kernel.org/stable/c/858576de6b2f5166b08dae803f0fd0766dcb3002 git.kernel.org: https://git.kernel.org/stable/c/7e07d3e4c389217d7d7171d80edf2e23ac70f1ea