{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64594","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.799Z","datePublished":"2026-08-06T07:13:50.309Z","dateUpdated":"2026-08-17T04:58:16.410Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:58:16.410Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: initialize reset_work at allocation time\n\nffs_fs_kill_sb() unconditionally calls cancel_work_sync() on\nffs->reset_work when a functionfs instance is unmounted:\n\n\tffs_data_reset(ffs);\n\tcancel_work_sync(&ffs->reset_work);\n\nHowever ffs->reset_work is only ever initialized via INIT_WORK() in\nffs_func_set_alt() and ffs_func_disable(), and only on the\nFFS_DEACTIVATED path. That state is reached solely by ffs_data_closed()\nwhen the instance is mounted with the \"no_disconnect\" option, so for the\ncommon case (no \"no_disconnect\", or mounted and unmounted without ever\nbeing deactivated) reset_work is never initialized.\n\nffs_data_new() allocates the ffs_data with kzalloc_obj() and does not\ninitialize reset_work, and ffs_data_reset()/ffs_data_clear() do not touch\nit either, so reset_work.func is left NULL. cancel_work_sync() on such a\nwork then trips the WARN_ON(!work->func) guard in __flush_work():\n\n  WARNING: kernel/workqueue.c:4301 at __flush_work+0x330/0x360, CPU#3: umount\n  Call trace:\n   __flush_work\n   cancel_work_sync\n   ffs_fs_kill_sb [usb_f_fs]\n   deactivate_locked_super\n   deactivate_super\n   cleanup_mnt\n   __cleanup_mnt\n   task_work_run\n   exit_to_user_mode_loop\n   el0_svc\n\nOn older kernels cancel_work_sync() on a zero-initialized work struct was\na silent no-op, which hid the missing initialization.\n\nInitialize reset_work once in ffs_data_new() so it is always valid for\nthe lifetime of the ffs_data, and drop the now-redundant INIT_WORK()\ncalls from the two deactivation paths."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/f_fs.c"],"versions":[{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"7fe895e0a9651518c4fc082487da770ff9c14c7f","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"cb19e54ebe9baf3c3243083ade65c937339ccb7b","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"d5631081be07f20e764d3cb5c98ac0a1004fba51","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"c36393b0d14e1e9783888f821ffe29381b8f46dc","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"69faa3779250df14f51d5084f938a99809546e52","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"ba1867999dbc4085e6d8c52ac5266005b8b2bf07","status":"affected","versionType":"git"},{"version":"18d6b32fca3841f7cd9479b4024abd8a9b299281","lessThan":"3137b243c93982fe3460335e12f9247739766e10","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/f_fs.c"],"versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7fe895e0a9651518c4fc082487da770ff9c14c7f"},{"url":"https://git.kernel.org/stable/c/0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7"},{"url":"https://git.kernel.org/stable/c/cb19e54ebe9baf3c3243083ade65c937339ccb7b"},{"url":"https://git.kernel.org/stable/c/d5631081be07f20e764d3cb5c98ac0a1004fba51"},{"url":"https://git.kernel.org/stable/c/c36393b0d14e1e9783888f821ffe29381b8f46dc"},{"url":"https://git.kernel.org/stable/c/69faa3779250df14f51d5084f938a99809546e52"},{"url":"https://git.kernel.org/stable/c/ba1867999dbc4085e6d8c52ac5266005b8b2bf07"},{"url":"https://git.kernel.org/stable/c/3137b243c93982fe3460335e12f9247739766e10"}],"title":"usb: gadget: f_fs: initialize reset_work at allocation time","x_generator":{"engine":"bippy-1.2.0"}}}}