Junglewise Threat Intelligence

CVE-2026-93121: Linux kernel USB gadget fence cleanup use-after-free

CVE-2026-93121 · Severity: high · CVSS 7 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's USB gadget function filesystem (f_fs) contains a bug in its DMABUF transfer error handling that can cause a system crash or undefined behavior. When certain error conditions occur during USB device data transfers, the kernel attempts to free memory incorrectly, leading to potential system instability. This affects systems that use USB gadget functionality, such as USB-based storage devices or custom USB peripherals.

Technical details

A use-after-free vulnerability exists in the ffs_dmabuf_transfer() function in drivers/usb/gadget/function/f_fs.c. In two error paths (ESHUTDOWN when endpoint is disabled, and ENOMEM during request allocation), the code calls dma_fence_put() on a fence object that has only been allocated with kmalloc() but not yet initialized via dma_fence_init(). At this stage, the fence's refcount and ops pointers are uninitialized, causing undefined behavior when dma_fence_put() attempts to dereference them. The fix replaces dma_fence_put() with kfree() in these error paths, since the fence is still a plain allocation at that point. Patches have been released in the Linux stable kernel trees.

Affected products

  • Linux Linux kernel Affected kernels since introduction of DMABUF import interface (7b07a2a7ca02); fix available in stable trees linux-5.15.y and later

Timeline

  • 2026-09-17: disclosed: Advisory published on NVD
  • 2026-06-12: patched: Fix authored by Nuno Sá
  • 2026-09-14: patched: Fix merged to stable kernel trees by Greg Kroah-Hartman

References

Related threats