SB2026091867 - Double free in Linux kernel gadget udc driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Double free (CVE-ID: CVE-2026-93141)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in r8a66597_probe() when usb_add_gadget_udc() fails. A local user can trigger the probe error path to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/150d3f3c461345b6c9ae784912cf1e49c8e5ff6b
- https://git.kernel.org/stable/c/41d541e3718db01668a4cd29815ee4b3b55f76d2
- https://git.kernel.org/stable/c/6648c470918371766f6d368113dd2a4faebac93f
- https://git.kernel.org/stable/c/6be64cca6527f7fc99b05abf54f22db91bbc116f
- https://git.kernel.org/stable/c/7721cf32efa428bd9649f4a9b89fc85601df87de
- https://git.kernel.org/stable/c/b2e68583c7c51eea2aafb8f1793e0d285c56ac82
- https://git.kernel.org/stable/c/c9e93290ffe7db22a8131a5f5fd026335090fbbe
- https://git.kernel.org/stable/c/f9c43246128a2dd0f2bbad71decf153910ce3606