Use-After-Free Vulnerability in Linux Kernel Affecting USB Device Management
CVE-2026-80824

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80824?

A use-after-free vulnerability exists in the Linux kernel's USB device management when handling the usb_device structure. In the process of releasing a USB device reference, the kernel drops the reference before completely draining the list of completed asynchronous requests (URBs). This creates a scenario where an unprivileged attacker can exploit the race condition by interacting with a USB device, leading to potential read from freed memory. Such exploitation may allow attackers to execute arbitrary code or cause system instability. It is crucial for users and administrators to apply updates and patches to the Linux kernel promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

Linux f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 < 0a960b88c5979f853019d4dc4957dfbeeb193440

Linux f7d34b445abc00e979b7cf36b9580ac3d1a47cd8 < 96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf

Linux f7d34b445abc00e979b7cf36b9580ac3d1a47cd8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.