Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()

Previously fsg_num_buffers_validate() was removed as it was not
necessary due to Kconfig setting the limits for n from 2 to 256 with
default as 2. However, setting the page content in such a way that
kstrtou8() reflects n value as either 0 or 1 bypasses these
restrictions leading to a null pointer dereference if n is 0. Fix
this by adding a check for n < 2 and returning -EINVAL if n is
either 0 or 1 consistent with Kconfig logic.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference occurs in the Linux kernel USB Mass Storage gadget driver when the buffer count configuration is set to 0 or 1, bypassing the intended minimum of 2. The driver attempts to set up pointers based on this value, and with a null pointer the kernel crashes. The crash results in a loss of system responsiveness and a kernel panic, potentially allowing an attacker to destabilize the device and force a reboot. Because the fault happens in kernel space, an attacker who can influence the gadget configuration may be able to exploit the crash to gain elevated privileges, though that scenario is not explicitly confirmed by the current information.

Affected Systems

All Linux systems that compile the f_mass_storage gadget driver into the kernel and do not apply the referenced patches are affected. The vulnerability is not tied to a specific kernel release in the advisory, which means any distribution or custom build that includes the unpatched driver is potentially vulnerable. Users of mainstream distributions with the default kernel configuration, as well as developers building custom kernels for embedded or IoT devices, should verify whether the driver is included and whether the patch has been applied.

Risk and Exploitability

The EPSS score indicates a probability of exploitation below 1%, and the vulnerability is not listed in CISA’s KEV catalogue, suggesting no widespread exploitation at present. Exploitation would require an attacker with access to the USB interface or the ability to modify gadget configuration data, implying a local or close-proximity attack vector. While the immediate effect is a denial of service via a kernel crash, the underlying null pointer could also be leveraged for privilege escalation if an attacker can trigger the crash repeatedly to influence kernel memory or control flow. The absence of a CVSS score does not negate the high impact of a kernel panic, but the low EPSS suggests the risk to most deployments remains moderate until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 07:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel update that includes the patch from commit 2c0f5ca48674a5b5f9fa4a9c3325aa48053af0bc or a later stable release.
  • If an update is not yet available, reconfigure the f_mass_storage gadget to set the buffer count to at least 2 or disable the fsg_num_buffers option to prevent the null pointer dereference.
  • If the mass storage gadget is not needed on the device, unload or remove the f_mass_storage module to eliminate the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 07:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Previously fsg_num_buffers_validate() was removed as it was not necessary due to Kconfig setting the limits for n from 2 to 256 with default as 2. However, setting the page content in such a way that kstrtou8() reflects n value as either 0 or 1 bypasses these restrictions leading to a null pointer dereference if n is 0. Fix this by adding a check for n < 2 and returning -EINVAL if n is either 0 or 1 consistent with Kconfig logic.
Title usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:57:00.276Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90023

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:15.250

Modified: 2026-10-03T11:17:45.837

Link: CVE-2026-90023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses