-

CVE-2026-64594

usb: gadget: f_fs: initialize reset_work at allocation time

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_fs: initialize reset_work at allocation time

ffs_fs_kill_sb() unconditionally calls cancel_work_sync() on
ffs->reset_work when a functionfs instance is unmounted:

	ffs_data_reset(ffs);
	cancel_work_sync(&ffs->reset_work);

However ffs->reset_work is only ever initialized via INIT_WORK() in
ffs_func_set_alt() and ffs_func_disable(), and only on the
FFS_DEACTIVATED path. That state is reached solely by ffs_data_closed()
when the instance is mounted with the "no_disconnect" option, so for the
common case (no "no_disconnect", or mounted and unmounted without ever
being deactivated) reset_work is never initialized.

ffs_data_new() allocates the ffs_data with kzalloc_obj() and does not
initialize reset_work, and ffs_data_reset()/ffs_data_clear() do not touch
it either, so reset_work.func is left NULL. cancel_work_sync() on such a
work then trips the WARN_ON(!work->func) guard in __flush_work():

  WARNING: kernel/workqueue.c:4301 at __flush_work+0x330/0x360, CPU#3: umount
  Call trace:
   __flush_work
   cancel_work_sync
   ffs_fs_kill_sb [usb_f_fs]
   deactivate_locked_super
   deactivate_super
   cleanup_mnt
   __cleanup_mnt
   task_work_run
   exit_to_user_mode_loop
   el0_svc

On older kernels cancel_work_sync() on a zero-initialized work struct was
a silent no-op, which hid the missing initialization.

Initialize reset_work once in ffs_data_new() so it is always valid for
the lifetime of the ffs_data, and drop the now-redundant INIT_WORK()
calls from the two deactivation paths.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < 7fe895e0a9651518c4fc082487da770ff9c14c7f
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < 0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < cb19e54ebe9baf3c3243083ade65c937339ccb7b
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < d5631081be07f20e764d3cb5c98ac0a1004fba51
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < c36393b0d14e1e9783888f821ffe29381b8f46dc
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < 69faa3779250df14f51d5084f938a99809546e52
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < ba1867999dbc4085e6d8c52ac5266005b8b2bf07
Status affected
Version 18d6b32fca3841f7cd9479b4024abd8a9b299281
Version < 3137b243c93982fe3460335e12f9247739766e10
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.0
Status affected
Version 0
Version < 4.0
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7fe895e0a9651518c4fc082487da770ff9c14c7f
https://git.kernel.org/stable/c/0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7
https://git.kernel.org/stable/c/cb19e54ebe9baf3c3243083ade65c937339ccb7b
https://git.kernel.org/stable/c/d5631081be07f20e764d3cb5c98ac0a1004fba51
https://git.kernel.org/stable/c/c36393b0d14e1e9783888f821ffe29381b8f46dc
https://git.kernel.org/stable/c/69faa3779250df14f51d5084f938a99809546e52
https://git.kernel.org/stable/c/ba1867999dbc4085e6d8c52ac5266005b8b2bf07
https://git.kernel.org/stable/c/3137b243c93982fe3460335e12f9247739766e10