๐Ÿ” CVE Alert

CVE-2026-90022

UNKNOWN 0.0

usb: gadget: f_midi2: fix use-after-free in string attribute show path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string attribute show path f_midi2_opts_str_show() takes the string lock internally, but its callers dereference the opts->info.<field> pointer before calling it, outside the lock. This races with f_midi2_opts_str_store(), which frees the old string under opts->lock when the attribute is written concurrently, the show path can read a pointer that gets freed before the lock inside str_show() is even taken. Change f_midi2_opts_str_show() to take a pointer to the string field, matching the existing pattern in f_midi2_opts_str_store(), and dereference it only after the lock is held. Update all three callers (iface_name, block name, and the EP string option macro) accordingly.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f9bdf4c4f6410a1dfafafa383a0e21069372657f 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d11f3300b39e2daad2f0d9d66ddcc39a156cb594 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e89e30f0b5d3004fe5955250bd8b04f3733e32ce 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 49fab5e1bdb205c36c965d0e9677bc40d282d3a2 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b 0 < 6.6.157 0 < 6.12.110 0 < 6.18.51 0 < 7.2.5
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f9bdf4c4f6410a1dfafafa383a0e21069372657f git.kernel.org: https://git.kernel.org/stable/c/d11f3300b39e2daad2f0d9d66ddcc39a156cb594 git.kernel.org: https://git.kernel.org/stable/c/e89e30f0b5d3004fe5955250bd8b04f3733e32ce git.kernel.org: https://git.kernel.org/stable/c/49fab5e1bdb205c36c965d0e9677bc40d282d3a2 git.kernel.org: https://git.kernel.org/stable/c/fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b