SB20260816208 - Use-after-free in Linux kernel usb
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74501)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to use-after-free in ump_to_endpoint() when handling a subsequent open of the exposed UMP device node after a malicious USB MIDI 2.0 device causes creation to fail. An attacker with physical access can connect a malicious USB MIDI 2.0 device to trigger the dangling pointer dereference and disclose sensitive information.
The issue occurs because the UMP endpoint remains registered and its device node stays exposed after the associated snd_usb_midi2_ump object has been freed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/49eccef6d6e1c00dac6fb2e7eb6f9206c33e1c37
- https://git.kernel.org/stable/c/4a05b2d1b4642df74f30b6f54843e825c4a2bfd3
- https://git.kernel.org/stable/c/8a7a33b846d6ba695891b8d0040027cdbad8cd52
- https://git.kernel.org/stable/c/ae388c0e1bf727972096f770f82d12e4f748d1b6
- https://git.kernel.org/stable/c/cc014ebf803174f0e5d15956dfc5a38413c945ae