Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()

In uvcg_video_init(), if kthread_run_worker() fails,
the error logged uses uvcg_err(), however, the pointer it uses:
video->uvc is not assigned at this point, triggering a null
pointer dereference. Fix this by directly using uvc->func which
is assigned already.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash due to null pointer dereference
Action: Apply kernel patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s USB gadget UVC driver. During device initialization, the error logging routine dereferences a pointer that has not yet been assigned. This results in a null pointer dereference that causes a kernel panic, interrupting service. The flaw is classified as CWE‑476 and does not provide privilege escalation or data disclosure.

Affected Systems

Linux kernels that load the g_uvc module for USB gadget UVC support are impacted. Any system where this module is enabled and the initialization path can be triggered, such as, is susceptible until the patch is applied.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% shows a very low expected exploitation probability. The likely attack vector is an attacker having the ability to supply a USB gadget device that activates the UVC driver’s initialization failure path, implying physical or local USB device injection rather than remote exploitation. Upon exploitation, the kernel panic results in a denial of service but does not leak information or grant elevated privileges. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 19:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit fixing the null pointer dereference.
  • Unload or disable the g_uvc module if a patch is not yet available, preventing the driverVC USB gadget devices or restrict USB policies to mitigate inadvertent activation of the driver.
  • Monitor system logs for UVC‑related crash entries to detect any remaining failure attempts.

Generated by OpenCVE AI on September 15, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() In uvcg_video_init(), if kthread_run_worker() fails, the error logged uses uvcg_err(), however, the pointer it uses: video->uvc is not assigned at this point, triggering a null pointer dereference. Fix this by directly using uvc->func which is assigned already.
Title usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:43.261Z

Reserved: 2026-09-11T19:38:34.760Z

Link: CVE-2026-89734

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:03.860

Modified: 2026-09-11T20:20:03.860

Link: CVE-2026-89734

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:43Z

Links: CVE-2026-89734 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses