Linux Kernel Vulnerability in Midi2 Gadget Configuration
CVE-2026-89735
Currently unrated
What is CVE-2026-89735?
In the Linux kernel, the midi2 gadget experiences a resource leak due to the absence of cleanup for default configfs child groups during function teardown. The function f_midi2_alloc_inst() allocates these groups but fails to remove them when necessary, resulting in leaked structures and unfreed resources. The implementation of configfs_remove_default_groups() in the relevant teardown processes will ensure that resources are properly released, thus enhancing system stability and security.
Affected Version(s)
Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 4beda67ee72e0c8df5b49951dd8b96f6adb25e02
Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87
Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 9ea5dfb2bfef4f8a7e704d1921d8a790cb7fb700