{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89733","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.760Z","datePublished":"2026-09-11T19:46:42.613Z","dateUpdated":"2026-09-14T12:02:21.384Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:21.384Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()\n\nIn uvc_function_bind() error path, we use usb_ep_free_request which\nuses uvc->control_req but does not set it to NULL afterwards. Thus,\nuvc->control_req is a dangling pointer causing a UAF. Also we do not set\nthe uvc->control_buf pointer to NULL after freeing it, which is another\ndangling pointer. Fix it by setting uvc->control_req to NULL after we run\nusb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the\nsame for uvc_function_unbind()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached by local writes to /sys/kernel/config/usb_gadget/<g>/UDC that drive uvc_function_bind()/uvc_function_unbind(); no USB host traffic or physical attachment is required, matching prior gadget bind dangling-pointer scores and being higher severity than Physical.\nAC:L - The attacker controls the successful bind, the unbind that leaves uvc->control_req dangling, and a later bind that fails before reallocating (e.g. exhausting usb_ep_autoconfig(), as in the syzkaller \"Unable to allocate streaming EP\" crash), so the error path double-frees the usb_request with no race.\nPR:L - gadget_dev_desc_UDC_store() and uvc_function_bind() perform no capability check; access is gated only by configfs permissions, and Android/embedded USB gadget HALs routinely delegate /sys/kernel/config/usb_gadget to non-root system or daemon accounts.\nUI:N - The attacker performs the configfs UDC bind/unbind writes themselves; no victim action, cable plug, or other-user interaction is required.\nS:U - The dangling usb_request double-free corrupts kernel heap within the same kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - usb_ep_free_request() on the stale control_req is a use-after-free of a usb_request slab object; an attacker who sprays that cache controls the freed object and can convert the UAF into kernel memory disclosure.\nI:H - The same stale pointer is a double-free through ep->ops->free_request, yielding classic heap-corruption primitives (object overlap and arbitrary free) that can be leveraged into arbitrary write and control-flow hijack.\nA:H - The syzkaller report is a KASAN slab-use-after-free oops in usb_ep_free_request() on the bind error path, and the double free independently panics the kernel, which the attacker can retrigger via configfs."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/f_uvc.c"],"versions":[{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"ddb1b0d5d858584ed0d3a5aaa042ee693998c7e2","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"85dd5e8bd6776d02854f2847d83429f1f712e99c","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"502a7f5b79b7ba751988789e982924f8f496129f","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"bec7708eb3b5295d12e931db24381b7c94c72953","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"8e88ed8a374de67270d38689f2a81018909cafbb","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"9897b7da8c0ad8356c1b8649379fcb5a689462cb","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"38f822ddce9355893d734279a26ddec45182197e","status":"affected","versionType":"git"},{"version":"0f9df939385527049c8062a099fbfa1479fe7ce0","lessThan":"bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc","status":"affected","versionType":"git"},{"version":"1efa8a5aac93d9e67075995d7d4902b57ce184f7","status":"affected","versionType":"git"},{"version":"e7a4b0efe62e56a0acc81d16091c6efc2a282be8","status":"affected","versionType":"git"},{"version":"065f5561a20659cf17aae5f72b32b5c2695c8e00","status":"affected","versionType":"git"},{"version":"3.2.36","lessThan":"3.3","status":"affected","versionType":"semver"},{"version":"3.4.25","lessThan":"3.5","status":"affected","versionType":"semver"},{"version":"3.7.2","lessThan":"3.8","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/f_uvc.c"],"versions":[{"version":"3.8","status":"affected"},{"version":"0","lessThan":"3.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.25"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ddb1b0d5d858584ed0d3a5aaa042ee693998c7e2"},{"url":"https://git.kernel.org/stable/c/85dd5e8bd6776d02854f2847d83429f1f712e99c"},{"url":"https://git.kernel.org/stable/c/502a7f5b79b7ba751988789e982924f8f496129f"},{"url":"https://git.kernel.org/stable/c/bec7708eb3b5295d12e931db24381b7c94c72953"},{"url":"https://git.kernel.org/stable/c/8e88ed8a374de67270d38689f2a81018909cafbb"},{"url":"https://git.kernel.org/stable/c/9897b7da8c0ad8356c1b8649379fcb5a689462cb"},{"url":"https://git.kernel.org/stable/c/38f822ddce9355893d734279a26ddec45182197e"},{"url":"https://git.kernel.org/stable/c/bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc"}],"title":"usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()","x_generator":{"engine":"bippy-1.2.0"}}}}