Junglewise Threat Intelligence

CVE-2026-64342: Linux Kernel iowarrior use-after-free on USB disconnect

CVE-2026-64342 · Severity: info · CVSS 4.6 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's driver for IOWarrior USB devices. When one of these devices is unplugged while data is still being written, the system may attempt to access memory that has already been freed. This can lead to a system crash or unpredictable behavior, potentially impacting the stability of industrial or specialized hardware setups using these USB interfaces.

Technical details

A use-after-free vulnerability was identified in drivers/usb/misc/iowarrior.c in the Linux kernel. The root cause is that submitted write USB Request Blocks (URBs) were not being stopped during the close() operation. Consequently, if a device is disconnected, these URBs could trigger a completion handler that attempts to access the device structure after it has been deallocated. An attacker with physical access to the device could potentially trigger this race condition by disconnecting the device during active write operations. The fix involves unconditionally killing anchored URBs during the disconnect() sequence to ensure no asynchronous handlers run after the device context is destroyed. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.21 to 6.6.145

Timeline

  • 2026-05-23: patched: Initial patch authored by Johan Hovold
  • 2026-07-25: disclosed: CVE published via kernel.org and NVD

References

Related threats