Description
In the Linux kernel, the following vulnerability has been resolved:

media: em28xx: defer audio-only extension registration

The audio-only path registers extensions while probing the primary device.
For a dual-TS board, this happens before dev_next is created. The duplicate
device inherits is_audio_only and is then independently inserted into
em28xx_devlist.

The list is intended to contain only primary devices: extension operations
reach the secondary device through dev_next. The independently linked
secondary can be freed during disconnect while its list node remains
reachable, resulting in a use-after-free.

Defer audio-only extension registration to the module-request work item. It
runs only after probing has completed construction of the optional
secondary device, so only the primary is registered and extension callbacks
reach the secondary through dev_next.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in em28xx media driver
Action: Update Kernel
AI Analysis

Impact

During device probing on boards that support dual time‑slot interfaces, the em28xx media driver registers audio‑only extensions before the optional secondary device is fully constructed. The driver then creates a duplicate device that inherits the audio‑only flag and is inserted into a global device list. Because the primary and secondary devices are linked independently, the secondary can be freed during a disconnect while its list node remains reachable, leading to a use‑after‑free condition. If an attacker can trigger the probe and disconnect sequence, they could exploit kernel memory corruption, potentially allowing arbitrary code execution at kernel privilege level.

Affected Systems

This weakness is found in the Linux kernel’s em28xx media driver. Any distribution or build of the Linux kernel that includes the unpatched em28xx code is affected. The advisory references commit identifiers that applied the fix, but no specific version range is listed; therefore, systems running pre‑fix kernels that provide em28xx support are at risk.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability that this vulnerability will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require local privileged access to invoke the driver’s probing logic, as remote exploitation pathways are not documented. Because the bug can lead to a kernel crash or arbitrary code execution, its potential impact is severe, but the overall likelihood of attack remains low at present.

Generated by OpenCVE AI on September 18, 2026 at 08:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the em28xx use‑after‑free patch (e.g., the commit referenced in the advisory).
  • Reboot the system to load the updated em28xx driver and ensure the new module is active.
  • If upgrading the kernel is not immediately feasible, disable or unload the em28xx audio driver on systems that do not require it to eliminate the vulnerable code path.

Generated by OpenCVE AI on September 18, 2026 at 08:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: em28xx: defer audio-only extension registration The audio-only path registers extensions while probing the primary device. For a dual-TS board, this happens before dev_next is created. The duplicate device inherits is_audio_only and is then independently inserted into em28xx_devlist. The list is intended to contain only primary devices: extension operations reach the secondary device through dev_next. The independently linked secondary can be freed during disconnect while its list node remains reachable, resulting in a use-after-free. Defer audio-only extension registration to the module-request work item. It runs only after probing has completed construction of the optional secondary device, so only the primary is registered and extension callbacks reach the secondary through dev_next.
Title media: em28xx: defer audio-only extension registration
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:54.665Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89892

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.870

Modified: 2026-09-16T11:16:57.870

Link: CVE-2026-89892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses