Junglewise Threat Intelligence

CVE-2026-89735: Linux kernel USB MIDI 2.0 gadget memory leak in configfs teardown

CVE-2026-89735 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's USB MIDI 2.0 gadget driver fails to properly release allocated memory structures when cleaning up configuration file system (configfs) groups during device teardown. This results in a memory leak that could gradually consume system memory over time if USB MIDI devices are repeatedly created and destroyed. The vulnerability impacts systems using the USB MIDI 2.0 function driver.

Technical details

The vulnerability is a resource leak in the USB MIDI 2.0 gadget function driver (f_midi2). The f_midi2_alloc_inst() function creates default configfs child groups (f_midi2_ep_opts and f_midi2_block_opts) using configfs_add_default_group(), which sets their reference count to 1. However, the corresponding teardown functions f_midi2_free_inst() and f_midi2_ep_opts_release() fail to call configfs_remove_default_groups() to drop these references, causing the structures to leak. The fix adds the missing configfs_remove_default_groups() calls in both teardown paths. This is a local/kernel-level issue with no network exposure; exploitation requires the ability to load/unload USB MIDI 2.0 gadget modules.

Affected products

  • Linux Linux kernel 6.0 and later (introduced in commit 8b645922b223)

Timeline

  • 2026-09-11: disclosed: CVE published
  • 2026-08-14: patched: Fix committed to mainline (commit 0f6bffb5008f0cba9cad5ded2caccc64466a6e54)
  • 2026-07-30: other: Fix authored by Joshua Crofts

References

Related threats