Linux Kernel Vulnerability in USB Gadget Implementation
CVE-2026-80854
What is CVE-2026-80854?
A flaw has been identified in the Linux kernel's USB gadget implementation where the port count can prematurely reach zero, leading to unintended session removal during command processing. Specifically, a race condition may occur when the last Logical Unit Number (LUN) is being removed concurrently with a nexus removal operation. This can result in attempting to access freed memory, causing instability and potential system crashes. To mitigate this, an additional callback has been proposed to ensure the port count remains non-zero until all active LUN references have been properly drained, thus safeguarding against premature session terminations.
Affected Version(s)
Linux c52661d60f636d17e26ad834457db333bd1df494
Linux c52661d60f636d17e26ad834457db333bd1df494
Linux c52661d60f636d17e26ad834457db333bd1df494 < 178f59a0bccd3f66cdfa5184310f31a58b7257c4