Race condition in Linux kernel - CVE-2026-68456
Published: August 17, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in the ueagle-atm USB driver disconnect handler when handling device removal during asynchronous pre-firmware loading. A local attacker can unplug a device while firmware loading is still in progress to cause a denial of service.
The issue is associated with the firmware sysfs fallback mechanism and manifests when device teardown runs concurrently with the asynchronous firmware request.
Affected software
How to mitigate CVE-2026-68456
External References
- https://git.kernel.org/stable/c/509b51327320bdeaef1969248177a446ded073ab
- https://git.kernel.org/stable/c/76861031b43a18065d13f9ffb8595d25c7576005
- https://git.kernel.org/stable/c/bbfedc84714064ea4845e6b76f96316eb5bb65d8
- https://git.kernel.org/stable/c/c581e30ae5b332d8acef64475a211b3f82099941
- https://git.kernel.org/stable/c/d85f19aaef42a03e3e4765d659c761c8750a7f23
- https://git.kernel.org/stable/c/ddcdac47e1f2651c7be60e299f98faf981522797
- https://git.kernel.org/stable/c/e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf
- https://git.kernel.org/stable/c/f2a6abc670104fc3e383ee3b1cf35c070485e3df