From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0F0D958FD0C for ; Fri, 11 Sep 2026 20:04:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157101; cv=none; b=WrCR9FB9xOje5JL/Bv/Bedpn4t7cznhaMcUKLYfaZmmvdY/mFSyeTZReS3tM7etIv4+JGUbQ6+BotIQ3Ihnt1vTu6q7i3q0tQdhgPyOsQN0yxuxSfkK9SU3yt8p3K2+fvTM624jK5NpGgGVbaAc/Hg+hkX3ZMbzuDP6ywMQyQBM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157101; c=relaxed/simple; bh=pkpDdJKQrkDVh2EFKdj+xRNONAtj4URvS1gIAKFZoA4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Neqa2m+RgEVO09suwDkfUBW+CAo8EFGazmpMgEhIFTsv0zX2Crd5u7XnNysu9TZArqAHwsPQV6B7BsFs/cakPm1es+2HftGWtZ1A4YGHjoxAQ4vLBbrimwIyi6k+IGLIlFe2+UXCcE6jvlT86/EQkKw7bDc9MX6D9uQTMLAXFX4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=T/5HhQx0; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="T/5HhQx0" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 13AD21F00893; Fri, 11 Sep 2026 20:04:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157093; bh=YVLzOo9geETI7s39xwyLk6lviCdm6Pqoa5Do7dft6Ao=; h=From:To:Cc:Subject:Date:Reply-To; b=T/5HhQx0IIerctovn6/LgIMfKyl1wwMmCIeBUVRwhkz/APpi5O6AfYw5wB5LzefS2 tIpanVuEvsnGZKC+/9WQWDvrXj8wS3yFy6i4/zYWtmVNZ8okcrFzB3jwXstVkGP1NY cwUAPpUNEVWakUMprUmbP6uV8cS3Mft+t1w/nWyE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89733: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() Date: Fri, 11 Sep 2026 21:47:02 +0200 Message-ID: <2026091103-CVE-2026-89733-950f@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2972; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=S4jK9C22C7O1wEwzW9QLAGeGs74wDis1BCPzFX4Aikc=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIruZft9yUHAoCsg8H8+zetXpHI3g6B2my3pXTzdyE 1pmkuHXEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABOp3c0wT83z+xnbHYlzNOa0 71hrcu7C4l+TlBkWbG+Uf+M1v0yx9mCCkMiPBTukleryAQ== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() In uvc_function_bind() error path, we use usb_ep_free_request which uses uvc->control_req but does not set it to NULL afterwards. Thus, uvc->control_req is a dangling pointer causing a UAF. Also we do not set the uvc->control_buf pointer to NULL after freeing it, which is another dangling pointer. Fix it by setting uvc->control_req to NULL after we run usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the same for uvc_function_unbind(). The Linux kernel CVE team has assigned CVE-2026-89733 to this issue. Affected and fixed versions =========================== Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 6.12.109 with commit 8e88ed8a374de67270d38689f2a81018909cafbb Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 6.18.50 with commit 9897b7da8c0ad8356c1b8649379fcb5a689462cb Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 7.2.4 with commit 38f822ddce9355893d734279a26ddec45182197e Issue introduced in 3.8 with commit 0f9df939385527049c8062a099fbfa1479fe7ce0 and fixed in 7.3-rc1 with commit bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc Issue introduced in 3.2.36 with commit 1efa8a5aac93d9e67075995d7d4902b57ce184f7 Issue introduced in 3.4.25 with commit e7a4b0efe62e56a0acc81d16091c6efc2a282be8 Issue introduced in 3.7.2 with commit 065f5561a20659cf17aae5f72b32b5c2695c8e00 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89733 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/usb/gadget/function/f_uvc.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/8e88ed8a374de67270d38689f2a81018909cafbb https://git.kernel.org/stable/c/9897b7da8c0ad8356c1b8649379fcb5a689462cb https://git.kernel.org/stable/c/38f822ddce9355893d734279a26ddec45182197e https://git.kernel.org/stable/c/bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc