Use-after-free in Linux kernel - CVE-2026-80824
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in usbdev_release() in usbfs when draining completed asynchronous URBs after a USB device is disconnected. A local user can mmap a usbfs device node and submit an asynchronous URB using a mapped buffer before unmapping and closing the associated file descriptor to cause a denial of service.
Affected software
How to mitigate CVE-2026-80824
External References
- https://git.kernel.org/stable/c/0a960b88c5979f853019d4dc4957dfbeeb193440
- https://git.kernel.org/stable/c/0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671
- https://git.kernel.org/stable/c/47a7f98fbb5006d46d15a3a210ffdc61448a4f19
- https://git.kernel.org/stable/c/5f08c45bdcfd28d1171de38c5ef29fc89a76eedc
- https://git.kernel.org/stable/c/65879e0a452ca2a234b9475e0c11aff7a4343738
- https://git.kernel.org/stable/c/7f0278e474c4d1c4457974ff1137cc385c944ab3
- https://git.kernel.org/stable/c/96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf
- https://git.kernel.org/stable/c/b3cde26a66b04f1d90ed0b675899c88b4e49d424
- https://git.kernel.org/stable/c/bd4bffc621a8cb2f4d9ed9b6447415de524a3bef