Junglewise Threat Intelligence

CVE-2026-64346: Linux Kernel use-after-free in USB gadget UDC core

CVE-2026-64346 · Severity: info · CVSS 5.5 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition in the Linux kernel's USB gadget subsystem could allow a local attacker to cause a system crash. The issue occurs when the system attempts to manage USB device controllers while they are simultaneously being disconnected or reconfigured. This primarily impacts system stability and availability, potentially leading to a denial-of-service.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's USB gadget subsystem within the gadget_match_driver function. The root cause is the decoupled lifecycles of the 'udc' management structure and the gadget itself. A race condition occurs when usb_del_gadget() frees the udc memory (often triggered by mode-switch work) while gadget_match_driver() concurrently attempts to access that same memory via configfs. This results in a NULL pointer dereference when the freed memory is zeroed. The fix introduces a new reference counting mechanism (usb_gadget_release) to ensure the udc structure remains allocated until the gadget is fully released. Patches have been merged into multiple stable kernel branches.

Affected products

  • Linux Linux Kernel All versions prior to fixed stable releases (e.g., 5.10.223, 5.15.164, 6.1.102, 6.6.43, 6.9.12, 6.10.2)

Timeline

  • 2026-06-25: disclosed: Initial patch submission by Jimmy Hu
  • 2026-07-24: patched: Commits merged into stable kernel trees
  • 2026-07-25: advisory: CVE-2026-64346 published

References

Related threats