SB20260905122 - Use-after-free in Linux kernel usb core driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80824)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in usbdev_release() in usbfs when draining completed asynchronous URBs after a USB device is disconnected. A local user can mmap a usbfs device node and submit an asynchronous URB using a mapped buffer before unmapping and closing the associated file descriptor to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0a960b88c5979f853019d4dc4957dfbeeb193440
- https://git.kernel.org/stable/c/0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671
- https://git.kernel.org/stable/c/47a7f98fbb5006d46d15a3a210ffdc61448a4f19
- https://git.kernel.org/stable/c/5f08c45bdcfd28d1171de38c5ef29fc89a76eedc
- https://git.kernel.org/stable/c/65879e0a452ca2a234b9475e0c11aff7a4343738
- https://git.kernel.org/stable/c/7f0278e474c4d1c4457974ff1137cc385c944ab3
- https://git.kernel.org/stable/c/96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf
- https://git.kernel.org/stable/c/b3cde26a66b04f1d90ed0b675899c88b4e49d424
- https://git.kernel.org/stable/c/bd4bffc621a8cb2f4d9ed9b6447415de524a3bef