Description
In the Linux kernel, the following vulnerability has been resolved:

media: em28xx: fix use-after-free of dev_next->devlist on disconnect

When a device with has_dual_ts=1 is probed and the is_audio_only path
is taken, both dev and dev->dev_next are added to the global
em28xx_devlist via em28xx_init_extension(). However, during disconnect,
em28xx_close_extension(dev) only calls list_del(&dev->devlist), leaving
dev->dev_next->devlist still linked in the global list. When dev_next is
subsequently freed via kref_put(), its devlist entry becomes a dangling
pointer in em28xx_devlist. The next device probe that calls
em28xx_init_extension() triggers a list corruption BUG when list_add_tail
detects the freed node.

This bug was exposed by commit a368ecde8a50 ("USB: core: Fix duplicate
endpoint bug by clearing reserved bits in the descriptor") which clears
reserved bits in bEndpointAddress during endpoint parsing. This causes
fuzzed endpoint addresses like 0xf3 to be normalized to 0x83, which
em28xx interprets as a vendor audio endpoint, enabling the
is_audio_only + has_dual_ts code path that was previously unreachable
with such descriptors.

Fix this by removing dev->dev_next->devlist from the global list in
em28xx_close_extension() before the device is freed.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash causing denial of service
Action: Upgrade Kernel
AI Analysis

Impact

In the Linux kernel media driver em28xx, a use‑after‑free bug allows a corrupted global device list to occur when a device with has_dual_ts=1 is disconnected. During disconnect the driver removes only the device’s own list entry, leaving the next element’s list pointer dangling. When a subsequent device probe adds a new device, the list corruption triggers a BUG, leading to a kernel panic.

Affected Systems

All systems running a Linux kernel that includes the em28xx driver before the patch that removes the dangling devlist reference are affected. The flaw is inherent in the kernel code and therefore any distribution shipping a kernel version with the em28xx module prior to the fix is vulnerable, irrespective of other components or services.

Risk and Exploitability

The EPSS score is below 1%, indicating a low probability of exploitation and the vulnerability is not listed in CISA KEV. The bug is triggered by a USB device that supplies fuzzed endpoint descriptors that cause the driver to execute the is_audio_only + has_dual_ts path. Exercising this path results in a list corruption and kernel crash, producing a denial‑of‑service attack vector.

Generated by OpenCVE AI on September 18, 2026 at 08:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the commit removing the dangling list reference from em28xx_close_extension().
  • If a kernel upgrade cannot be performed immediately, apply a local patch that deletes the dev_next->devlist entry from the global list before freeing the device to prevent the list corruption at disconnect time.
  • Restrict the use of USB devices that could supply fuzzed endpoint descriptors by limiting physical USB port access to trusted devices only, thereby reducing the chance of triggering the vulnerable driver path.

Generated by OpenCVE AI on September 18, 2026 at 08:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free of dev_next->devlist on disconnect When a device with has_dual_ts=1 is probed and the is_audio_only path is taken, both dev and dev->dev_next are added to the global em28xx_devlist via em28xx_init_extension(). However, during disconnect, em28xx_close_extension(dev) only calls list_del(&dev->devlist), leaving dev->dev_next->devlist still linked in the global list. When dev_next is subsequently freed via kref_put(), its devlist entry becomes a dangling pointer in em28xx_devlist. The next device probe that calls em28xx_init_extension() triggers a list corruption BUG when list_add_tail detects the freed node. This bug was exposed by commit a368ecde8a50 ("USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor") which clears reserved bits in bEndpointAddress during endpoint parsing. This causes fuzzed endpoint addresses like 0xf3 to be normalized to 0x83, which em28xx interprets as a vendor audio endpoint, enabling the is_audio_only + has_dual_ts code path that was previously unreachable with such descriptors. Fix this by removing dev->dev_next->devlist from the global list in em28xx_close_extension() before the device is freed.
Title media: em28xx: fix use-after-free of dev_next->devlist on disconnect
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:53.963Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.740

Modified: 2026-09-16T11:16:57.740

Link: CVE-2026-89891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses