Null-Pointer Dereference in Linux Kernel USB MIDI Gadget
CVE-2026-90024

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90024?

A null-pointer dereference vulnerability has been identified in the Linux kernel's USB MIDI gadget functionality. The issue arises during the cleanup of an endpoint not properly initialized, leading to a system crash when attempting to stop uninitialized endpoints. When the block direction for the MIDI 2.0 gadget is configured incorrectly, the initialization for certain endpoints is skipped, causing a dereference of a NULL pointer during operation. This vulnerability emphasizes the importance of proper endpoint initialization to maintain system stability.

Affected Version(s)

Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 51ddc55c75087ac25342f6d73d3aeaf14f59bd76

Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 5b92f6a0c7c01efbb335d837ecdf34d38d98720f

Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 9c3d5091e3568ed48ac4c5b08a78eb06fad0d70a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.