SB2026091778 - Use-after-free in Linux kernel usb em28xx driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89892)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to trigger a use-after-free.
The vulnerability exists due to improper device list management in the em28xx audio-only extension registration path when connecting and disconnecting a dual-TS board. An attacker with physical access can connect and disconnect a dual-TS board to trigger a use-after-free.
The condition affects audio-only paths on dual-TS boards.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0da1e627f4fc9d0e947fdae90913042120878923
- https://git.kernel.org/stable/c/1abe9524dec0fd26e9ceb8d586034d6f68dd8273
- https://git.kernel.org/stable/c/4666197ca4f7d80cd3b0292054fe45d76be9ba04
- https://git.kernel.org/stable/c/4e11c45dfdc72ab656067b1df8fcebaf52fd4715
- https://git.kernel.org/stable/c/95f76f51937fdfb0fc1e14cae606b1ef574a56f3
- https://git.kernel.org/stable/c/d06067ee32620f272cfb80c7bc7c572ad4e74724
- https://git.kernel.org/stable/c/f8d7e77d9c621b42a191c67a9b37bec23dc1d555
- https://git.kernel.org/stable/c/f9322ac9f862961d7f377b87ec26c8565af7e073