Use-after-free in Linux kernel - CVE-2026-68372
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the USB Type-C connector handling in drivers/usb/core/port.c when processing Thunderbolt dock unplug and concurrent partner-disconnect events. A local user can trigger a crafted hot-unplug race to cause a denial of service.
Exploitation requires a race between component unbind, USB disconnect, and UCSI partner-disconnect handling during dock hot-plug events.
Affected software
Ubuntu
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-68372
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13