Linux Kernel Memory Management Vulnerability in USB Gadget f_midi Module
CVE-2026-90021

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90021?

A memory management vulnerability in the Linux kernel's USB gadget f_midi module arises due to improper initialization of work structures in the f_midi_alloc function. This can lead to a scenario where the related work is not initialized, resulting in warnings when flushed. The issue is addressed by ensuring that the initialization of work is performed directly in f_midi_alloc, preventing potential runtime errors.

Affected Version(s)

Linux 8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 3d8b11255e632170f32f1925bfcaf96331f36317

Linux 8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 02ac76f27db23ef652358458c272d9d2d6f51167

Linux 8653d71ce3763aedcf3d2331f59beda3fecd79e4 < 858576de6b2f5166b08dae803f0fd0766dcb3002

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.