Junglewise Threat Intelligence

CVE-2026-90019: Linux kernel USB gadget null pointer dereference in usb_put_function_instance

CVE-2026-90019 · Severity: info · Published 2026-09-16

Executive brief

The Linux kernel's USB gadget subsystem contains a null pointer dereference vulnerability in the usb_put_function_instance() function. When error handling occurs during USB function initialization, the code attempts to access a field that has not yet been allocated, causing a kernel crash. This can lead to denial of service on systems using USB gadget functionality.

Technical details

The vulnerability is a null pointer dereference in the USB gadget driver (drivers/usb/gadget/functions.c). The usb_put_function_instance() function attempts to dereference the fd (function driver) field within the fi (function instance) struct without first checking if fd is null. In the error path of uvc_alloc_inst(), the fi struct is allocated but fd is not yet initialized, and thus guaranteed to be null at that point. The fix adds a null check for fi->fd before dereferencing it. No special authentication or user interaction is required—the vulnerability can be triggered during normal USB gadget initialization failure scenarios.

Affected products

  • Linux Linux kernel All versions with USB gadget support (likely 5.x and later)

Timeline

  • 2026-09-16: disclosed: CVE-2026-90019 published
  • 2026-09-14: patched: Fix committed to Linux stable trees

References

Related threats