Null-Pointer Dereference in Linux Kernel USB MIDI Gadget
CVE-2026-90024
What is CVE-2026-90024?
A null-pointer dereference vulnerability has been identified in the Linux kernel's USB MIDI gadget functionality. The issue arises during the cleanup of an endpoint not properly initialized, leading to a system crash when attempting to stop uninitialized endpoints. When the block direction for the MIDI 2.0 gadget is configured incorrectly, the initialization for certain endpoints is skipped, causing a dereference of a NULL pointer during operation. This vulnerability emphasizes the importance of proper endpoint initialization to maintain system stability.
Affected Version(s)
Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 51ddc55c75087ac25342f6d73d3aeaf14f59bd76
Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 5b92f6a0c7c01efbb335d837ecdf34d38d98720f
Linux 8b645922b22303cec4628dbbbf6c8553d1cdec87 < 9c3d5091e3568ed48ac4c5b08a78eb06fad0d70a