Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()

In uvc_function_bind() error path, we use usb_ep_free_request which
uses uvc->control_req but does not set it to NULL afterwards. Thus,
uvc->control_req is a dangling pointer causing a UAF. Also we do not set
the uvc->control_buf pointer to NULL after freeing it, which is another
dangling pointer. Fix it by setting uvc->control_req to NULL after we run
usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the
same for uvc_function_unbind().
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free
Action: Apply patch
AI Analysis

Impact

A flaw in the Linux kernel’s USB gadget UVC driver causes two pointers, uvc->control_req and uvc->control_buf, to stay dangling after they are freed in the bind and unbind functions. This results in a use‑after‑free that corrupts kernel memory and can lead to a crash or, in worst cases, local privilege escalation.

Affected Systems

The vulnerability affects and has not yet incorporated the upstream fix. Specific kernel version numbers are not listed, so all kernels shipping an unpatched UVC module are potentially impacted. It is inferred that systems that disable or omit the UVC gadget driver are not affected, as no UVC code would execute.

Risk and Exploitability

The CVSS base score of 7.8 indicates a medium‑to‑high impact, while the suggests a low current exploitation likelihood. The vulnerability is not in CISA’s KEV catalog. Attackers would need to trigger the buggy bind or unbind paths, likely by interacting with the USB gadget interface or by loading the module in a privileged context. No publicly available exploits are documented, but successful exploitation could cause a kernel crash or enable privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream kernel patch that nulls control_req and control_buf after freeing them
  • Upgrade to a Linux kernel version that includes the UVC gadget driver fix
  • If an update cannot be applied, blacklist or unload the uvc gadget module to prevent it from loading

Generated by OpenCVE AI on September 15, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() In uvc_function_bind() error path, we use usb_ep_free_request which uses uvc->control_req but does not set it to NULL afterwards. Thus, uvc->control_req is a dangling pointer causing a UAF. Also we do not set the uvc->control_buf pointer to NULL after freeing it, which is another dangling pointer. Fix it by setting uvc->control_req to NULL after we run usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the same for uvc_function_unbind().
Title usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:21.384Z

Reserved: 2026-09-11T19:38:34.760Z

Link: CVE-2026-89733

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:03.730

Modified: 2026-09-14T13:19:22.430

Link: CVE-2026-89733

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:42Z

Links: CVE-2026-89733 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference