Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89739

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition<br /> <br /> In dwc3_gadget_init_endpoint, &amp;dep-&gt;nostream_work is bound with<br /> dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue<br /> this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM<br /> event is received.<br /> <br /> If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and<br /> the memory allocated for dep with kzalloc() is released by kfree(dep),<br /> while the delayed work mentioned above may still be pending or<br /> running. The sequence of operations that may lead to a UAF bug is as<br /> follows:<br /> <br /> CPU0 CPU1<br /> <br /> | dwc3_thread_interrupt<br /> | dwc3_endpoint_interrupt<br /> | dwc3_gadget_endpoint_stream_event<br /> | queue_delayed_work(system_percpu_wq,<br /> | &amp;dep-&gt;nostream_work)<br /> dwc3_gadget_free_endpoints |<br /> dwc3_free_trb_pool(dep) |<br /> list_del(&amp;dep-&gt;endpoint.ep_list) |<br /> dwc3_debugfs_remove_endpoint_dir(dep) |<br /> kfree(dep) |<br /> // dep is freed |<br /> | dwc3_nostream_work<br /> | // use dep (use-after-free)<br /> <br /> Fix it by canceling the delayed work before kfree(dep) in<br /> dwc3_gadget_free_endpoints.

Impacto