Description
In the Linux kernel, the following vulnerability has been resolved:

usb: storage: realtek_cr: fix use-after-free on disconnect

realtek_cr_destructor() calls timer_delete() before the chip containing
the timer is freed. The timer callback may still be running and can
rearm itself, resulting in a use-after-free.

Use timer_shutdown_sync() to wait for the callback and prevent further
rearming. Do this unconditionally because ss_en may be changed after
the timer is armed.

Move timer_setup() into init_realtek_cr() so the timer is initialized
before any failure path can invoke the destructor.

Found by static analysis.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a use‑after‑free condition in the Realtek CR USB storage driver of the Linux kernel. During device disconnection, the destructor calls timer_delete on a timer object that has not yet completed its callback. The timer callback may still be executing and can rearm itself, leading to a use‑after‑free. This flaw provides an available vector for arbitrary code execution or memory corruption when an attacker can trigger the disconnect sequence.

Affected Systems

All Linux kernel deployments that include the Realtek CR USB storage driver before the patch. The CPE indicates the general Linux kernel, so any distribution using a kernel version with the unpatched driver is potentially affected. No specific version ranges were given, so it is assumed all current kernels are impacted until the commit is merged.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a use‑after‑free is a high‑severity weakness that can lead to privilege escalation or denial of service. Inference suggests that the attack requires the ability to manipulate a Realtek CR USB device or send a crafted disconnect notification; local privileged users could exploit it, and a remote attacker might gain access if the device is exposed via a networked host that accepts USB attachments. No additional prerequisites are noted, so the primary limitation is the presence of the Realtek CR hardware and the ability to cause a breakpoint on disconnect.

Generated by OpenCVE AI on September 17, 2026 at 23:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the patch (merge commit 4ffee1aebb0c0ffcda9faffd17834ea9b00d42cc, 7c4e2f964c65dea4ea22386799d5fb10ef1e3e54, or cae9dbba6adae21a04a3bd045e07b489847ff2c6).
  • If an immediate kernel update is not possible, disable the Realtek CR USB storage driver or unplug any Realtek CR devices until the patch is applied.
  • After applying the patch or disabling the driver, reboot the system to ensure that all timer resources are cleared and the vulnerability is removed.

Generated by OpenCVE AI on September 17, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disconnect realtek_cr_destructor() calls timer_delete() before the chip containing the timer is freed. The timer callback may still be running and can rearm itself, resulting in a use-after-free. Use timer_shutdown_sync() to wait for the callback and prevent further rearming. Do this unconditionally because ss_en may be changed after the timer is armed. Move timer_setup() into init_realtek_cr() so the timer is initialized before any failure path can invoke the destructor. Found by static analysis.
Title usb: storage: realtek_cr: fix use-after-free on disconnect
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:57:01.352Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:15.953

Modified: 2026-10-03T11:17:45.943

Link: CVE-2026-90029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:30:17Z

Weaknesses