Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi2: fix use-after-free in string attribute show path

f_midi2_opts_str_show() takes the string lock internally, but its
callers dereference the opts->info.<field> pointer before calling it,
outside the lock. This races with f_midi2_opts_str_store(), which
frees the old string under opts->lock when the attribute is written
concurrently, the show path can read a pointer that gets freed
before the lock inside str_show() is even taken.

Change f_midi2_opts_str_show() to take a pointer to the string field,
matching the existing pattern in f_midi2_opts_str_store(), and
dereference it only after the lock is held. Update all three callers
(iface_name, block name, and the EP string option macro) accordingly.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel exposes a use‑after‑free condition in the f_midi2 USB gadget when the string attribute show path is accessed concurrently with a write. The flaw arises because the show routine dereferences a pointer that may have been freed by a parallel store operation, allowing an attacker to read a dangling pointer and potentially trigger kernel memory corruption. The vulnerability is a classic Use‑After‑Free (CWE‑416) and could lead to a crash or, if exploited further, local privilege escalation or code execution.

Affected Systems

Linux kernels that include the USB gadget f_midi2 driver prior to the patch. The affected code paths involve the opts_str_show functions used for exposing device attributes. No specific kernel versions are listed, so any kernel build containing the f_midi2 driver without the fix is potentially vulnerable. The vulnerability is present in both the generic Linux kernel and any derivative distributions that ship the driver unpatched.

Risk and Exploitability

The final CVSS score of 7.8 indicates a high severity with potential for local code execution. The EPSS score is less than 1 %, suggesting low exploitation probability as of now, and the advisory is not present in CISA’s KEV catalog. The attack vector is likely local, requiring access to the f_midi2 sysfs attributes, but an attacker could trigger the race condition by performing a concurrent read and write. Successful exploitation could crash the kernel or provide a foothold for further privilege escalation.

Generated by OpenCVE AI on September 18, 2026 at 07:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest kernel version that incorporates the f_midi2 use‑after‑free fix.
  • If an upgrade is not possible, recompile the kernel without the f_midi2 gadget driver or disable it at runtime.
  • Ensure that only privileged accounts can write to the f_midi2 sysfs attributes via appropriate file permissions.
  • Monitor system logs for abnormal kernel panics or crashes that might indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 07:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string attribute show path f_midi2_opts_str_show() takes the string lock internally, but its callers dereference the opts->info.<field> pointer before calling it, outside the lock. This races with f_midi2_opts_str_store(), which frees the old string under opts->lock when the attribute is written concurrently, the show path can read a pointer that gets freed before the lock inside str_show() is even taken. Change f_midi2_opts_str_show() to take a pointer to the string field, matching the existing pattern in f_midi2_opts_str_store(), and dereference it only after the lock is held. Update all three callers (iface_name, block name, and the EP string option macro) accordingly.
Title usb: gadget: f_midi2: fix use-after-free in string attribute show path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:26.435Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90022

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:15.140

Modified: 2026-09-17T10:17:05.910

Link: CVE-2026-90022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses