Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi: initialize work in f_midi_alloc()

f_midi_alloc initializes free_ref to 1 and it can only be incremented
when a sound card is registered via f_midi_register_card().
f_midi_register_card() is only called in f_midi_bind() which actually
performs INIT_WORK. If f_midi_bind() is never run, work is not
initialized and the if condition in f_midi_free becomes true,
this results in a warning later in __flush_work as work->func = 0.
Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential Kernel Crash / Denial of Service
Action: Apply Patch
AI Analysis

Impact

f_midi_alloc initializes a reference counter that can only be incremented when a sound card is registered via f_midi_register_card(). Because INIT_WORK was incorrectly placed in f_midi_bind(), the work structure for the MIDI gadget might remain uninitialized if bind never runs. When the kernel later calls __flush_work, the work structure’s function pointer is null, causing a warning and potentially a kernel panic. The flaw is an unsafe use of an uninitialized object (CWE‑824).

Affected Systems

All Linux kernel releases that expose the f_midi gadget driver before the fix are affected. The vulnerability is present in kernel sources that include the original f_midi_alloc and f_midi_bind implementations, before the change that moves INIT_WORK into f_midi_alloc. No specific kernel series is listed, so any customer running an unpatched Linux kernel that supports the f_midi gadget should consider themselves at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, but the EPSS score of less than 1 % shows a very low exploitation probability at the time of assessment. The vulnerability is not listed in CISA’s KEV catalog, reinforcing that it is not currently known to be widely exploited. Attackers would need local access to manipulate USB traffic to an uninitialized MIDI gadget; therefore the vector is local and requires some level of kernel interaction. Given the limited exploitation likelihood, it is recommended to patch rather than monitor.

Generated by OpenCVE AI on September 18, 2026 at 04:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that moves INIT_WORK into f_midi_alloc
  • Upgrade the Linux kernel to a version that contains this fix
  • If a kernel update is impossible, disable the USB MIDI gadget driver or block USB traffic that targets the f_midi subsystem

Generated by OpenCVE AI on September 18, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi_register_card(). f_midi_register_card() is only called in f_midi_bind() which actually performs INIT_WORK. If f_midi_bind() is never run, work is not initialized and the if condition in f_midi_free becomes true, this results in a warning later in __flush_work as work->func = 0. Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().
Title usb: gadget: f_midi: initialize work in f_midi_alloc()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:25.560Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90021

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:15.030

Modified: 2026-09-16T11:17:15.030

Link: CVE-2026-90021

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-90021 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer