Executive brief
A race condition was identified in the Linux kernel's USB Video Class (UVC) gadget driver. This issue occurs when a privileged user simultaneously attempts to bind a USB gadget while removing extension unit directories via configfs. While this could theoretically lead to a system crash (use-after-free), it is primarily considered a correctness fix as it requires administrative privileges to trigger.
Technical details
A race condition exists in `drivers/usb/gadget/function/f_uvc.c` because `uvc_function_bind()` iterates through extension units (XU) without holding the necessary `opts->lock`. This allows a concurrent `rmdir` operation in configfs (via `uvcg_extension_drop`) to delete an extension unit while it is being accessed, resulting in a use-after-free (UAF) of `struct uvcg_extension`. The vulnerability is reachable only by privileged processes capable of mounting configfs and writing to gadget UDC files. The fix involves holding the mutex across the XU descriptor walks to synchronize with configfs operations.
Affected products
- Linux Linux Kernel 0525210c9840229e42c6b68e886c72a75a67cf8e
Timeline
- 2026-07-24: advisory: CVE-2026-64233 published by NVD
- 2026-06-09: patched: Fix committed to stable kernel tree by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/2c9e0905ef7e69f7b814cd709613f6b3b5b98805
- https://git.kernel.org/stable/c/5f1b9cff88982e2a2053d8b1fd983f7ccb9f03cc
- https://git.kernel.org/stable/c/68aa70648b625fa684bc0b71bbfd905f4943ca20
- https://git.kernel.org/stable/c/caec0145e5974e85fe5192fc6a6f5aa1a98f82a6
- https://git.kernel.org/stable/c/e15c414092b3c24610cc771e481a723b0f645eca