SB2026080770 - Use-after-free in Linux kernel gadget function driver
Published: August 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-64584)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the f_midi driver work handler when handling concurrent userspace writes to an open rawmidi substream during device teardown. A local user can write to a rawmidi substream to trigger pending work on a freed midi object and cause a denial of service.
The issue occurs because the rawmidi device can remain usable by an open substream after USB endpoints have been disabled and before the final midi object reference is released.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9
- https://git.kernel.org/stable/c/5650c18d93a1db7e27cb5a40b394747eb4686d5b
- https://git.kernel.org/stable/c/87bc316dd6fc90072297c635e10b9aa6075ecda1
- https://git.kernel.org/stable/c/ac9a51d910bb7465c554c45320cb6c09f3d0b49d
- https://git.kernel.org/stable/c/f45089eaad0a083d71d84ff175741d7e157d9b69