Description
In the Linux kernel, the following vulnerability has been resolved:

USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()

gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but
dev->state is checked after acquiring the lock. Therefore a concurrent
bind can change the device state between these operations, which can
leave ioctl with a stale NULL gadget pointer and causing a NULL pointer
dereference at gadget->ops->ioctl.

Read dev->gadget while holding dev->lock so that the gadget pointer
and device state are sampled consistently.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (application crash)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a race in gadget_dev_ioctl where the dev->gadget pointer is read before acquiring dev->lock, while the dev->state check occurs afterwards. A concurrent bind can change the device state between these operations, leaving ioctl with a stale NULL gadget pointer that is dereferenced through gadget->ops->ioctl. This results in a kernel crash, producing a denial‑of‑service for the host system. The weakness manifests as a null pointer dereference and a concurrency problem.

Affected Systems

The flaw affects the generic Linux kernel, with no specific version range listed in the advisory. Any system using a kernel build that includes gadget_dev_ioctl before the patch commit is potentially vulnerable.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector requires local execution by a process that can invoke the USB gadget ioctl interface; it does not require network access. The impact is a local denial of service through a kernel crash, with the risk tempered by the low exploit probability.

Generated by OpenCVE AI on September 18, 2026 at 04:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel version that includes the gadget_dev_ioctl fix, such as the latest patched release from the upstream Linux kernel series.
  • If immediate kernel upgrade is not possible, disable or restrict the USB gadget subsystem (for example, remove or unload gadget drivers, or set the gadget authorized flag to 0) to eliminate the attack surface until the patch can be applied.
  • Keep the system monitored for any kernel oops or crash logs that indicate gadget-related crashes, so that the vulnerability impact can be assessed and mitigated promptly.

Generated by OpenCVE AI on September 18, 2026 at 04:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but dev->state is checked after acquiring the lock. Therefore a concurrent bind can change the device state between these operations, which can leave ioctl with a stale NULL gadget pointer and causing a NULL pointer dereference at gadget->ops->ioctl. Read dev->gadget while holding dev->lock so that the gadget pointer and device state are sampled consistently.
Title USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:25.203Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:14.903

Modified: 2026-09-17T10:17:05.793

Link: CVE-2026-90020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:15:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-476

    NULL Pointer Dereference