Executive brief
The Linux kernel's USB Dual-Role controller (dwc3) gadget driver contains a use-after-free vulnerability in its endpoint cleanup code. When a USB gadget is removed while a delayed work task is pending, the freed endpoint structure can be accessed by the work function, potentially causing a kernel crash or data corruption that could disrupt system stability and availability.
Technical details
This vulnerability is a use-after-free (CWE-416) in dwc3_gadget_free_endpoints, occurring when a race condition allows a delayed work handler (dwc3_nostream_work) to execute after its associated endpoint structure has been freed. The vulnerable component is the dwc3 USB gadget driver's endpoint management code. An attacker with the ability to trigger USB gadget insertion/removal cycles while stream events are being processed can exploit this condition. The attack requires no authentication and operates at the kernel level; no user interaction is strictly required beyond gadget device control. A successful exploit results in a kernel memory access violation, potentially causing a denial-of-service crash. The fix, already implemented in the referenced kernel commit, cancels pending delayed work tasks before freeing the endpoint structure.
Affected products
- Linux Linux kernel <UNKNOWN>
Timeline
- 2026-09-11: disclosed
- 2026-09-11: advisory