Linux Kernel Vulnerability Affecting USB Type-C Functionality
CVE-2026-90027

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90027?

A vulnerability in the Linux Kernel's USB Type-C implementation allows delayed work callbacks to run after cleanup operations, potentially causing device management issues. Specifically, when the port is stopped, queued callbacks may execute after resources have been freed, leading to unstable behavior. A fix has been implemented by disabling delayed work synchronization during the port stop process to ensure callbacks do not interfere with the cleanup of the type-C port.

Affected Version(s)

Linux a4422ff221429c600c3dc5d0394fb3738b89d040 < 4359b5f95c93a4658e08368fa6fab9d89eb98447

Linux a4422ff221429c600c3dc5d0394fb3738b89d040

Linux a4422ff221429c600c3dc5d0394fb3738b89d040 < 1ab669c2b44e1040ddfab7cd7f717aad580d17aa

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.