Junglewise Threat Intelligence

CVE-2026-64242: Linux Kernel double free in net2280 USB gadget driver

CVE-2026-64242 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's net2280 USB gadget driver, which is used to manage certain USB peripheral controllers. A flaw in how the system handles errors during device setup could lead to a system crash or instability (double free). This typically requires local access to the system or the ability to trigger specific hardware initialization failures.

Technical details

A double-free vulnerability exists in drivers/usb/gadget/udc/net2280.c within the net2280_probe() function. The issue arises because usb_initialize_gadget() registers a release callback (gadget_release) that automatically frees the net2280 instance when the device reference count reaches zero. In the error handling path, the code calls net2280_remove(), which triggers usb_put_gadget() and subsequent freeing via the callback, but then incorrectly calls kfree(dev) again on the same object. An attacker with the ability to trigger a probe failure could cause a kernel panic or memory corruption. The issue has been resolved by removing the redundant kfree() call in the error path.

Affected products

  • Linux Linux Kernel 5.10 to 6.9.x

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats