Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed

In polled-VBUS mode (board.vbus_pin && board.vbus_polled), probe arms a
self-restarting cycle: at91_vbus_timer() schedules vbus_timer_work, and
at91_vbus_timer_work() calls at91_vbus_update() and re-arms the timer via
mod_timer(). Both recover the same udc through container_of and dereference
it on every iteration.

Neither teardown path cancels this cycle. udc is devm-allocated, so it is
freed after at91udc_remove() returns, and is likewise freed when probe
fails and devres runs. A timer callback or work item that is pending or
running at either point dereferences the freed udc.

Add at91_udc_shutdown_vbus_timer() and call it from at91udc_remove() and
from the usb_add_gadget_udc() failure path in probe; the remaining probe
error paths fail before the timer is armed. timer_shutdown_sync() waits
for a running callback and clears timer->function, which makes the work
handler's mod_timer() a permanent no-op; cancel_work_sync() then drains
any pending or running work whose re-arm attempt now does nothing. The
timer must be shut down first, since cancelling the work alone would let
the timer re-queue it. The guard mirrors probe: in IRQ mode the timer and
work_struct are never initialized.

This does not require a fault; a normal driver unbind can interleave with
an already queued work item.

This issue was found by an in-house static analysis tool.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel crash and denial of service
Action: Update Kernel
AI Analysis

Impact

The vulnerability is a use‑after‑free in the at91_udc USB gadget driver (CWE‑825). In polled‑VBUS mode, the driver creates a self‑starting timer that repeatedly re‑arms itself. Neither the removal routine nor the probe error paths cancel this cycle. When the driver or work handler still runs and accesses the released structure, it simply crashes the kernel, which results in a denial of service to the local system.

Affected Systems

Linux kernels that include the at91 module polled‑VBUS mode (.vbus_polled set). All distributions or embedded builds shipping this driver with polled‑VBUS enabled fall under the scope of the vulnerability.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of less than 1% indicates it is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires local access to the device while the timer is active or to cause denial of service by crashing the kernel, and remote exploitation is not supported.

Generated by OpenCVE AI on September 15, 2026 at 21:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel or driver update that includes the at91_udc_shutdown_vbus_timer fix.
  • Reboot the system to clear any pending timers or work items that may reference the freed driver.
  • If an update is not possible, disable the at91_udc driver or reconfigure the system to avoid polled‑VBUS mode.

Generated by OpenCVE AI on September 15, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed In polled-VBUS mode (board.vbus_pin && board.vbus_polled), probe arms a self-restarting cycle: at91_vbus_timer() schedules vbus_timer_work, and at91_vbus_timer_work() calls at91_vbus_update() and re-arms the timer via mod_timer(). Both recover the same udc through container_of and dereference it on every iteration. Neither teardown path cancels this cycle. udc is devm-allocated, so it is freed after at91udc_remove() returns, and is likewise freed when probe fails and devres runs. A timer callback or work item that is pending or running at either point dereferences the freed udc. Add at91_udc_shutdown_vbus_timer() and call it from at91udc_remove() and from the usb_add_gadget_udc() failure path in probe; the remaining probe error paths fail before the timer is armed. timer_shutdown_sync() waits for a running callback and clears timer->function, which makes the work handler's mod_timer() a permanent no-op; cancel_work_sync() then drains any pending or running work whose re-arm attempt now does nothing. The timer must be shut down first, since cancelling the work alone would let the timer re-queue it. The guard mirrors probe: in IRQ mode the timer and work_struct are never initialized. This does not require a fault; a normal driver unbind can interleave with an already queued work item. This issue was found by an in-house static analysis tool.
Title usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:49.071Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89738

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.357

Modified: 2026-09-13T07:17:38.550

Link: CVE-2026-89738

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:45Z

Links: CVE-2026-89738 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference