SB2026052789 - Improper control of a resource through its lifetime in Linux kernel can usb driver
Published: May 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-46103)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource lifetime management in the ucan USB driver control message buffer when drivers are unbound without physical device disconnection. A local user can trigger driver unbind conditions to cause a denial of service.
This can occur during probe deferral or configuration changes.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/10b7b676b78a7bd888d19729b459aad7fc1f428b
- https://git.kernel.org/stable/c/4b7d07747400cfd7eff1ba7b8b5a7c8d5a58f705
- https://git.kernel.org/stable/c/c0d3ccc6929e4509076df8f30a4fb1dc5018b0ae
- https://git.kernel.org/stable/c/c524c124e3094d2de12235a513854c03d06a2b58
- https://git.kernel.org/stable/c/fed4626501c871890da287bec62a96e52da1af89