Linux Kernel Vulnerability in USB Gadget Driver by Atmel
CVE-2026-89738

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89738?

A vulnerability exists in the USB gadget driver of the Linux kernel that may lead to the dereferencing of freed memory. This occurs due to a timer mechanism in polled-VBUS mode that schedules a self-restarting cycle without cancelling pending operations during the driver teardown process. Consequently, if a timer callback or work item is still executing while the driver is removed, it may attempt to access memory that has already been deallocated. This flawed implementation can result in unstable behavior or crashes, leading to potential security risks within the affected systems.

Affected Version(s)

Linux 4037242c4f5ff77afe61bf07ca1e8a99490219e5

Linux 4037242c4f5ff77afe61bf07ca1e8a99490219e5 < 51a311eb97e91ce1aed3005cb71ccb2e30f8cce8

Linux 4037242c4f5ff77afe61bf07ca1e8a99490219e5 < 557ef547d49ff5e6026a4d39bdd3113bd81d7688

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.