Linux Kernel Vulnerability in USB Gadget Driver by Atmel
CVE-2026-89738
What is CVE-2026-89738?
A vulnerability exists in the USB gadget driver of the Linux kernel that may lead to the dereferencing of freed memory. This occurs due to a timer mechanism in polled-VBUS mode that schedules a self-restarting cycle without cancelling pending operations during the driver teardown process. Consequently, if a timer callback or work item is still executing while the driver is removed, it may attempt to access memory that has already been deallocated. This flawed implementation can result in unstable behavior or crashes, leading to potential security risks within the affected systems.
Affected Version(s)
Linux 4037242c4f5ff77afe61bf07ca1e8a99490219e5
Linux 4037242c4f5ff77afe61bf07ca1e8a99490219e5 < 51a311eb97e91ce1aed3005cb71ccb2e30f8cce8
Linux 4037242c4f5ff77afe61bf07ca1e8a99490219e5 < 557ef547d49ff5e6026a4d39bdd3113bd81d7688