Junglewise Threat Intelligence

CVE-2026-64343: Linux Kernel ldusb use-after-free in USB disconnect race

CVE-2026-64343 · Severity: info · CVSS 4.6 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB driver for LD devices could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when a USB device is disconnected at the same time the driver is attempting to release its resources, leading to a memory error. This could impact system stability and availability in environments where these specific USB devices are used.

Technical details

A use-after-free vulnerability exists in the Linux kernel USB ldusb driver (drivers/usb/misc/ldusb.c). The root cause is a race condition between ld_usb_release() and ld_usb_disconnect() where mutex_unlock() may access the mutex structure after the underlying object has been freed. Because mutex_unlock() is non-atomic and may access the lock object after releasing it, it cannot safely manage the lifetime of the driver data structure without additional reference counting. An attacker with local access or the ability to trigger USB disconnect events could exploit this race to cause a kernel panic or potentially achieve local privilege escalation. The fix introduces kref reference counting to ensure the driver data is only freed after all references, including those held during mutex operations, are released.

Affected products

  • Linux Linux Kernel 2.6.26 to 5.10.261

Timeline

  • 2026-06-22: patched: Initial patch authored by Johan Hovold
  • 2026-07-25: disclosed: CVE-2026-64343 published

References

Related threats