Description
In the Linux kernel, the following vulnerability has been resolved:

usb: fix UAF when probe runs concurrent to dyn ID removal

Dynamic IDs are only guaranteed to be valid when usb_dynids_lock is held,
as remove_id_store can free the node. Thus, make a copy in
usb_probe_interface. Clarify the documentation that the id parameter is
only valid during the probe.

USB serial has the same pattern, but it does not need fixing as the IDs
cannot be removed via sysfs.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free in USB Driver
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a Use‑After‑Free (CWE-364) that occurs when the USB driver performs a probe operation concurrently with the removal of a dynamic USB ID. A node that has been freed can still be accessed, allowing an attacker to corrupt memory or crash the kernel. The change fixes this by making a copy of the ID during probe and clarifying that the ID parameter is only valid during the probe operation.

Affected Systems

All Linux kernel builds are potentially affected until the patch is deployed. The vendor listing identifies Linux:Linux; versions are not specified in the CNA data, so the vulnerability may exist in any kernel revision lacking this fix.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a local attacker with USB access can trigger the flaw by connecting a crafted USB device while a device with a dynamic ID is undergoing removal. Successful exploitation could lead to a denial‑of‑service crash or possible privilege escalation, depending on system configuration. The CVSS severity is not explicitly stated, but the use‑after‑free nature suggests a potential high impact if leveraged.

Generated by OpenCVE AI on September 19, 2026 at 08:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel update that includes the UAF fix to the usb subsystem.
  • Reboot the system to load the updated kernel.
  • If an immediate patch is not feasible, disable dynamic USB ID removal in sysfs until the update is applied.

Generated by OpenCVE AI on September 19, 2026 at 08:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-364

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when usb_dynids_lock is held, as remove_id_store can free the node. Thus, make a copy in usb_probe_interface. Clarify the documentation that the id parameter is only valid during the probe. USB serial has the same pattern, but it does not need fixing as the IDs cannot be removed via sysfs.
Title usb: fix UAF when probe runs concurrent to dyn ID removal
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:24.509Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:06.300

Modified: 2026-09-17T17:18:06.300

Link: CVE-2026-93117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-364

    Signal Handler Race Condition