Use-after-free in Linux kernel - CVE-2026-89891
Published: September 17, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to use-after-free in the em28xx device-list handling during extension closure when disconnecting a dual transport-stream device through the audio-only path. An attacker with physical access can connect a USB device with crafted endpoint descriptors to cause a denial of service.
Affected software
How to mitigate CVE-2026-89891
External References
- https://git.kernel.org/stable/c/0782807552b6aff41b4656c6c9076a3231d3e79d
- https://git.kernel.org/stable/c/16cb1ee17e093175b4d9ae33202f68e5b108cca2
- https://git.kernel.org/stable/c/1ed575b1991f68569eb589b7747d3bc26aa6a8a2
- https://git.kernel.org/stable/c/20aacd87550be297dc39a3f9532dcfff91586510
- https://git.kernel.org/stable/c/20c2c65f3d9f7c278dc9750531d3201ac8bf78b7
- https://git.kernel.org/stable/c/826915b6b65e2d3251e7248ea54289a22d748c84
- https://git.kernel.org/stable/c/da4b07da6281e39ce4c01e1227e036f3bf600e14
- https://git.kernel.org/stable/c/f61720346fdcc1a2deec59a2f6cbb0cc20d1dc18