Junglewise Threat Intelligence

CVE-2026-64341: Linux Kernel USB iowarrior use-after-free in disconnect race

CVE-2026-64341 · Severity: info · CVSS 4.6 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB iowarrior driver, which manages specialized USB input/output devices. A race condition occurs when a device is disconnected while being accessed by a program, potentially causing the system to crash or behave unpredictably. This could lead to a denial of service or, in specific scenarios, allow an attacker to gain unauthorized access to system memory.

Technical details

A use-after-free (UAF) vulnerability in drivers/usb/misc/iowarrior.c arises because mutex_unlock() is used to manage the lifetime of the driver data structure. Since mutex_unlock() is non-atomic and may access the mutex structure after releasing the lock, a race condition between iowarrior_release() and iowarrior_disconnect() can result in the structure being freed while still in use. The fix introduces kref reference counting to ensure the driver data is only released after all active references, including those held during the unlock sequence, are cleared. This vulnerability typically requires local access or the ability to physically trigger USB disconnect events.

Affected products

  • Linux Linux Kernel 2.6.21 to 6.12.97, 7.1.4

Timeline

  • 2026-06-22: patched: Initial fix committed to mainline kernel
  • 2026-07-25: advisory: CVE-2026-64341 published

References

Related threats