From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-89733: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
Date: Fri, 11 Sep 2026 21:47:02 +0200 [thread overview]
Message-ID: <2026091103-CVE-2026-89733-950f@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
In uvc_function_bind() error path, we use usb_ep_free_request which
uses uvc->control_req but does not set it to NULL afterwards. Thus,
uvc->control_req is a dangling pointer causing a UAF. Also we do not set
the uvc->control_buf pointer to NULL after freeing it, which is another
dangling pointer. Fix it by setting uvc->control_req to NULL after we run
usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the
same for uvc_function_unbind().
The Linux kernel CVE team has assigned CVE-2026-89733 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 6.12.109 with commit 8e88ed8a374de67270d38689f2a81018909cafbb
Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 6.18.50 with commit 9897b7da8c0ad8356c1b8649379fcb5a689462cb
Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 7.2.4 with commit 38f822ddce9355893d734279a26ddec45182197e
Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 7.3-rc1 with commit bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc
Issue introduced in 3.2.36 with commit 1efa8a5aac93d9e67075995d7d4902b57ce184f7
Issue introduced in 3.4.25 with commit e7a4b0efe62e56a0acc81d16091c6efc2a282be8
Issue introduced in 3.7.2 with commit 065f5561a20659cf17aae5f72b32b5c2695c8e00
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89733
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/usb/gadget/function/f_uvc.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/8e88ed8a374de67270d38689f2a81018909cafbb
https://git.kernel.org/stable/c/9897b7da8c0ad8356c1b8649379fcb5a689462cb
https://git.kernel.org/stable/c/38f822ddce9355893d734279a26ddec45182197e
https://git.kernel.org/stable/c/bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc
reply other threads:[~2026-09-11 20:04 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026091103-CVE-2026-89733-950f@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.