Description
In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition

In dwc3_gadget_init_endpoint, &dep->nostream_work is bound with
dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue
this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM
event is received.

If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and
the memory allocated for dep with kzalloc() is released by kfree(dep),
while the delayed work mentioned above may still be pending or
running. The sequence of operations that may lead to a UAF bug is as
follows:

CPU0 CPU1

| dwc3_thread_interrupt
| dwc3_endpoint_interrupt
| dwc3_gadget_endpoint_stream_event
| queue_delayed_work(system_percpu_wq,
| &dep->nostream_work)
dwc3_gadget_free_endpoints |
dwc3_free_trb_pool(dep) |
list_del(&dep->endpoint.ep_list) |
dwc3_debugfs_remove_endpoint_dir(dep) |
kfree(dep) |
// dep is freed |
| dwc3_nostream_work
| // use dep (use-after-free)

Fix it by canceling the delayed work before kfree(dep) in
dwc3_gadget_free_endpoints.
Published: 2026-09-11
Score: 7.0 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel use‑after‑free causing memory corruption in the dwc3 USB gadget driver
Action: Immediate patch
AI Analysis

Impact

The bug is a use‑after‑free triggered by a race between a call that frees a dwc3 gadget endpoint and a delayed work item that still accesses that endpoint. If the delayed work runs after the endpoint is released, the kernel dereferences a stale pointer, corrupting memory and potentially allowing an attacker to execute arbitrary code in kernel mode or crash the system. This vulnerability falls under CWE‑825.

Affected Systems

All Linux kernel builds that include the dwc3 USB gadget driver – whether compiled into the kernel or loaded as a module – are affected. Because the vendor product listing is generic, the vulnerability applies to every kernel release that ships this driver until the patch that cancels the delayed work is applied.

Risk and Exploitability

The exploitation probability (EPSS) is reported as less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploits yet. The CVSS score of 7.0 classifies the issue as high severity, underscoring the seriousness of the potential kernel memory corruption. The likely attack vector would involve a malicious USB device or a user exposing a device to the system while a stream event is queued. An attacker would need to trigger gadget removal concurrently with the stream event to create the race condition. Although the risk of exploitation is low, the potential impact is high – any successful attack would elevate privileges to kernel level or cause a denial of service.

Generated by OpenCVE AI on September 21, 2026 at 01:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream kernel patch that cancels the delayed work before freeing the endpoint, as referenced in the commits linked in the advisory.
  • If a patched kernel is not available, disable the dwc3 gadget driver module – for example, add ‘blacklist dwc3’ to a modprobe configuration file and reboot to clear outstanding workqueue items.
  • If disabling the module is not an option, backport the commit to your current kernel source, rebuild the kernel, and boot into the patched image.

Generated by OpenCVE AI on September 21, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Mon, 14 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 13 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 13 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 13 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 13 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition In dwc3_gadget_init_endpoint, &dep->nostream_work is bound with dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM event is received. If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and the memory allocated for dep with kzalloc() is released by kfree(dep), while the delayed work mentioned above may still be pending or running. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | dwc3_thread_interrupt | dwc3_endpoint_interrupt | dwc3_gadget_endpoint_stream_event | queue_delayed_work(system_percpu_wq, | &dep->nostream_work) dwc3_gadget_free_endpoints | dwc3_free_trb_pool(dep) | list_del(&dep->endpoint.ep_list) | dwc3_debugfs_remove_endpoint_dir(dep) | kfree(dep) | // dep is freed | | dwc3_nostream_work | // use dep (use-after-free) Fix it by canceling the delayed work before kfree(dep) in dwc3_gadget_free_endpoints.
Title usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:46.545Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89739

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.480

Modified: 2026-09-11T20:20:04.480

Link: CVE-2026-89739

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T00:00:00Z

Links: CVE-2026-89739 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference