Junglewise Threat Intelligence

CVE-2026-64347: Linux Kernel NULL pointer dereference in USB gadget composite driver

CVE-2026-64347 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB gadget subsystem, which handles how the computer acts as a USB device. Under specific conditions, such as a race condition during device disconnection, the system could attempt to access invalid memory. This could lead to a system crash (denial of service) or potentially allow unauthorized access to small amounts of kernel memory.

Technical details

A vulnerability exists in the USB_DT_OTG handler within `drivers/usb/gadget/composite.c`. The `composite_setup()` function uses `list_first_entry()` to retrieve a configuration when none is selected; however, `list_first_entry()` does not return NULL on an empty list, rendering the subsequent NULL check ineffective. If `cdev->configs` is empty—due to a teardown race during gadget unbind or improper driver initialization—the code performs a `memcpy` from an invalid offset, leading to a KASAN fault or out-of-bounds read. The fix replaces the call with `list_first_entry_or_null()` to ensure the empty list condition is correctly handled.

Affected products

  • Linux Linux Kernel 53e6242db8d6 to 01feaf024f29618d5ffa7ab0fd858e0579dcbf7b

Timeline

  • 2026-05-27: disclosed: Initial patch submitted by Maoyi Xie
  • 2026-07-25: advisory: CVE-2026-64347 published

References

Related threats