Executive brief
A vulnerability was identified in the Linux kernel's USB gadget subsystem, which handles how the computer acts as a USB device. Under specific conditions, such as a race condition during device disconnection, the system could attempt to access invalid memory. This could lead to a system crash (denial of service) or potentially allow unauthorized access to small amounts of kernel memory.
Technical details
A vulnerability exists in the USB_DT_OTG handler within `drivers/usb/gadget/composite.c`. The `composite_setup()` function uses `list_first_entry()` to retrieve a configuration when none is selected; however, `list_first_entry()` does not return NULL on an empty list, rendering the subsequent NULL check ineffective. If `cdev->configs` is empty—due to a teardown race during gadget unbind or improper driver initialization—the code performs a `memcpy` from an invalid offset, leading to a KASAN fault or out-of-bounds read. The fix replaces the call with `list_first_entry_or_null()` to ensure the empty list condition is correctly handled.
Affected products
- Linux Linux Kernel 53e6242db8d6 to 01feaf024f29618d5ffa7ab0fd858e0579dcbf7b
Timeline
- 2026-05-27: disclosed: Initial patch submitted by Maoyi Xie
- 2026-07-25: advisory: CVE-2026-64347 published
References
- https://git.kernel.org/stable/c/01feaf024f29618d5ffa7ab0fd858e0579dcbf7b
- https://git.kernel.org/stable/c/2454264b2ab4cf0055c0bfd39e79f830452bd0db
- https://git.kernel.org/stable/c/56add2b9b2e89ec61c0761165d758f73004fdfdf
- https://git.kernel.org/stable/c/8ac463fe6c0f85bdb1ce8c30e8c9e060802e4483
- https://git.kernel.org/stable/c/91b3ecd34b60f950c50c560974945b6596a6f207
- https://git.kernel.org/stable/c/d3e72cfef2e38bd588055739a8100d14f9773b17
- https://git.kernel.org/stable/c/f8f680609c2b3ab795ffcd6f21585b6dfc46d395