Improper control of a resource through its lifetime in Linux kernel - CVE-2026-46103
Published: May 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource lifetime management in the ucan USB driver control message buffer when drivers are unbound without physical device disconnection. A local user can trigger driver unbind conditions to cause a denial of service.
This can occur during probe deferral or configuration changes.
How to mitigate CVE-2026-46103
Sources
- https://git.kernel.org/stable/c/10b7b676b78a7bd888d19729b459aad7fc1f428b
- https://git.kernel.org/stable/c/4b7d07747400cfd7eff1ba7b8b5a7c8d5a58f705
- https://git.kernel.org/stable/c/c0d3ccc6929e4509076df8f30a4fb1dc5018b0ae
- https://git.kernel.org/stable/c/c524c124e3094d2de12235a513854c03d06a2b58
- https://git.kernel.org/stable/c/fed4626501c871890da287bec62a96e52da1af89