Use-after-free in Linux kernel - CVE-2026-64340
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the legousbtower USB driver when handling a race between device release and disconnect. A local user can trigger the race condition by opening and releasing the device while it is being disconnected to cause a denial of service.
The issue arises from object lifetime management during concurrent disconnect and release operations.
How to mitigate CVE-2026-64340
Sources
- https://git.kernel.org/stable/c/0b57e5ddbd89df3bc367463de3d2ca66f99a1a5e
- https://git.kernel.org/stable/c/11d069f85851997b4ea0adf242ed9672dc749b8f
- https://git.kernel.org/stable/c/62fc8eb1b1481051f7bab4aa93d79809053dd09f
- https://git.kernel.org/stable/c/6462de75d2e370c7e74dcfb7b4ae79eb5a6a55ee
- https://git.kernel.org/stable/c/766738ecf2b819e54d38763c8d1c8ae6cff14b39
- https://git.kernel.org/stable/c/9ba62966461a8e3cc593b62c56ec62eb2d80436d
- https://git.kernel.org/stable/c/ab2bfd7bec4f134b377ec42f513e90c35db94160
- https://git.kernel.org/stable/c/b4222c05066b252b451f9c8c4730b5b60824ea66