Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: r8a66597: avoid double free of ep0_req in probe error path

If usb_add_gadget_udc() fails, r8a66597_probe() jumps to err_add_udc
and frees ep0_req, then falls through to clean_up2 where ep0_req is
freed again when it is non-NULL.

Remove the redundant free from err_add_udc and keep the cleanup in
clean_up2 so the request is released exactly once.

Issue found using a prototype static analysis tool
and confirmed by code review.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential for arbitrary code execution due to double free of a USB gadget request in the kernel
Action: Assess Impact
AI Analysis

Impact

The flaw exists in the Linux kernel’s USB gadget driver for r8a66597. During probe, if usb_add_gadget_udc() fails, the code frees the ep0_req structure twice: once in the err_add_udc path and again in clean_up2. This double free can corrupt heap memory and may allow an attacker with suitable privileges to execute arbitrary code or crash the system. The weakness is a classic double free bug.

Affected Systems

Any system running a Linux kernel that includes the r8a66597 gadget driver and has the driver compiled or loaded. The vulnerability is present in the source tree where the patch is applied; specific version numbers are not provided in the data, so affected releases must be verified against the Linux kernel commit that introduced the fix.

Risk and Exploitability

The CVSS score is not supplied, but the EPSS indicates the exploitation probability is below 1%, suggesting limited known exploitation activity. The vulnerability is not listed in the CISA KEV catalog, which further implies a lower likelihood of widespread attacks. Inferred from the description, the typical attack vector would require local or kernel‑level privileges to load or interact with the affected USB gadget driver. Nevertheless, a double free can lead to severe consequences, so administrators should treat it as a high‑risk bug.

Generated by OpenCVE AI on September 19, 2026 at 07:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the r8a66597 double‑free fix.
  • If a kernel update cannot be applied immediately, disable or unload the r8a66597 USB gadget driver until the patch is available.
  • Implement additional runtime memory protection, such as enabling ASLR and strict memory‑corruption mitigations, to reduce the impact of any remaining heap vulnerabilities.

Generated by OpenCVE AI on September 19, 2026 at 07:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: r8a66597: avoid double free of ep0_req in probe error path If usb_add_gadget_udc() fails, r8a66597_probe() jumps to err_add_udc and frees ep0_req, then falls through to clean_up2 where ep0_req is freed again when it is non-NULL. Remove the redundant free from err_add_udc and keep the cleanup in clean_up2 so the request is released exactly once. Issue found using a prototype static analysis tool and confirmed by code review.
Title usb: gadget: r8a66597: avoid double free of ep0_req in probe error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:40.761Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.130

Modified: 2026-09-17T17:18:09.130

Link: CVE-2026-93141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:13Z

Weaknesses