Junglewise Threat Intelligence

CVE-2026-64329: Linux kernel use-after-free in USB Type-C UCSI CCG driver

CVE-2026-64329 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB Type-C connector driver. When the driver is removed from the system, a race condition could allow the system to attempt to use memory that has already been freed. This could lead to a system crash or unpredictable behavior during hardware removal or system shutdown.

Technical details

A use-after-free vulnerability exists in drivers/usb/typec/ucsi/ucsi_ccg.c in the Linux kernel. The ucsi_ccg_remove() function calls ucsi_destroy(), which frees the 'ucsi' structure, before calling free_irq(). If a threaded interrupt handler (ccg_irq_handler) is already in flight, it may attempt to access the freed 'ucsi' object via ucsi_notify_common(). The fix reorders the removal path to ensure the interrupt is disabled and freed before the underlying data structures are destroyed. This issue was identified via static analysis.

Affected products

  • Linux Linux kernel e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2

Timeline

  • 2026-07-25: advisory: CVE-2026-64329 published
  • 2026-07-24: patched: Fix committed to stable tree

References

Related threats