CVE-2026-89739

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition<br /> <br /> In dwc3_gadget_init_endpoint, &amp;dep-&gt;nostream_work is bound with<br /> dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue<br /> this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM<br /> event is received.<br /> <br /> If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and<br /> the memory allocated for dep with kzalloc() is released by kfree(dep),<br /> while the delayed work mentioned above may still be pending or<br /> running. The sequence of operations that may lead to a UAF bug is as<br /> follows:<br /> <br /> CPU0 CPU1<br /> <br /> | dwc3_thread_interrupt<br /> | dwc3_endpoint_interrupt<br /> | dwc3_gadget_endpoint_stream_event<br /> | queue_delayed_work(system_percpu_wq,<br /> | &amp;dep-&gt;nostream_work)<br /> dwc3_gadget_free_endpoints |<br /> dwc3_free_trb_pool(dep) |<br /> list_del(&amp;dep-&gt;endpoint.ep_list) |<br /> dwc3_debugfs_remove_endpoint_dir(dep) |<br /> kfree(dep) |<br /> // dep is freed |<br /> | dwc3_nostream_work<br /> | // use dep (use-after-free)<br /> <br /> Fix it by canceling the delayed work before kfree(dep) in<br /> dwc3_gadget_free_endpoints.

Impact