Description
In the Linux kernel, the following vulnerability has been resolved:

USB: gadget: ffs: fix mm lifetime handling

io_data stores a pointer to the submitting task's mm_struct,
but does not currently hold a reference to it while async
requests are pending.

This can result in a use-after-free if the task exits before
completion handling finishes.

Take a reference with mmgrab() when queuing the read request
and release it with mmdrop() on request completion.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that may enable privilege escalation
Action: Patch immediately
AI Analysis

Impact

In the Linux kernel, the ffs USB gadget driver stores a pointer to the submitting task's mm_struct in the io_data structure but fails to hold a reference to it while asynchronous requests are pending. If the submitting task exits before the request completion handling finishes, the mm_struct can be freed, leading to a use‑after‑free condition. This kernel memory corruption may allow an attacker to influence kernel data structures, potentially resulting in privilege escalation or arbitrary code execution within the kernel context.

Affected Systems

The vulnerability affects all Linux kernel releases that do not include the patch commits referenced in the advisory (e.g. 5eb5c72c72fef, 7411de0ce3b45286de1de82526795658ea6eacb0). Target systems running an unpatched Linux kernel may therefore be exposed.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity, while the EPSS score is below 1%. The vulnerability is not listed in CISA’s KEV catalogue. Exploitation likely requires an attacker’s ability to configure a USB gadget that issues asynchronous FFS read requests while causing the submitting task to terminate prematurely, which typically implies physical access or control over the USB subsystem. Although the low EPSS score suggests infrequent exploitation, the impact of a kernel memory corruption is significant and warrants prompt action.

Generated by OpenCVE AI on September 18, 2026 at 04:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fix for commit 5eb5c72c72fef76cb765ef1669b62b6a3ba1bfc8 and related changes.
  • If an upgrade cannot be performed immediately, disable the ffs USB gadget driver by removing or blacklisting the module (e.g., "modprobe –r ffs" or adding a blacklist entry).
  • As a temporary measure, avoid running tasks that use the FFS driver and terminate abruptly; ensure any such tasks remain active until the driver completes processing any pending asynchronous requests.

Generated by OpenCVE AI on September 18, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it while async requests are pending. This can result in a use-after-free if the task exits before completion handling finishes. Take a reference with mmgrab() when queuing the read request and release it with mmdrop() on request completion.
Title USB: gadget: ffs: fix mm lifetime handling
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:19.588Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.763

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-90045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses