Use-After-Free Vulnerability in Linux Kernel Affects DWC3 Gadget
CVE-2026-89739

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89739?

A vulnerability in the Linux kernel's DWC3 gadget component exposes systems to a use-after-free condition due to race conditions in delayed work handling. When the gadget is removed, the cleanup sequence may lead to a scenario where memory, released for a specific endpoint, could still be accessed by queued delayed tasks, compromising system integrity. To address this vulnerability, cancelling the delayed work before memory deallocation is necessary to ensure safe memory management and operational stability.

Affected Version(s)

Linux dcfe437492e27d54f3ac491aed024da760f5c43c < 448e95c0f3eaa8d99f16ccae92ab94545f14413b

Linux dcfe437492e27d54f3ac491aed024da760f5c43c < 93e08b13a7a30e4e78556d993720e0bc36231ec7

Linux dcfe437492e27d54f3ac491aed024da760f5c43c < 9c855832790cd488d87de1885974f4c37cfe7358

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.