Executive brief
A vulnerability was identified in the Linux kernel's net2280 USB gadget driver, which is used to manage certain USB peripheral controllers. A flaw in how the system handles errors during device setup could lead to a system crash or instability (double free). This typically requires local access to the system or the ability to trigger specific hardware initialization failures.
Technical details
A double-free vulnerability exists in drivers/usb/gadget/udc/net2280.c within the net2280_probe() function. The issue arises because usb_initialize_gadget() registers a release callback (gadget_release) that automatically frees the net2280 instance when the device reference count reaches zero. In the error handling path, the code calls net2280_remove(), which triggers usb_put_gadget() and subsequent freeing via the callback, but then incorrectly calls kfree(dev) again on the same object. An attacker with the ability to trigger a probe failure could cause a kernel panic or memory corruption. The issue has been resolved by removing the redundant kfree() call in the error path.
Affected products
- Linux Linux Kernel 5.10 to 6.9.x
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://git.kernel.org/stable/c/085652fda7f38040d1a2c42d72614f418feb843f
- https://git.kernel.org/stable/c/48f89ead20e48d447ad29fa937b43b9fa981cf28
- https://git.kernel.org/stable/c/550fa4d071a8c8e53072900869d37ae6abf4999d
- https://git.kernel.org/stable/c/71b3391dc81655ff058492f8e9d013b2c6e5747b
- https://git.kernel.org/stable/c/c5b9fdb1e8ddf50bc6272927edb118679f170350
- https://git.kernel.org/stable/c/c8547c74988e0b5f4cbb1b895e2a57aae084f070
- https://git.kernel.org/stable/c/db2b72e83a0208ae2b3b270bf91662b1c6849a9b