Use-after-free in Linux kernel - CVE-2026-68367
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the f_tcm delayed set_alt work handler when processing delayed USB gadget alternate-setting changes during disconnect or function teardown. A local user can trigger function unlink or teardown while delayed set_alt work is still pending to cause a denial of service.
The issue was reproduced by KASAN in tcm_delayed_set_alt after the function state was freed through configfs unlink operations.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68367
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/3118bb872c7dff653294f193d5328a476619e04d
- https://git.kernel.org/stable/c/4c6c6a5588b9a2f8437fb794e852d05fa60ebe53
- https://git.kernel.org/stable/c/79e2d75725c85607f8a9d87ae9cace62a19f767d
- https://git.kernel.org/stable/c/a6eb5a0ae7cd313cfd7df78decd8f43b64c68703
- https://git.kernel.org/stable/c/f282242906c12fd476b86757afba51f211d4f959