7.8

CVE-2026-90022

usb: gadget: f_midi2: fix use-after-free in string attribute show path

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi2: fix use-after-free in string attribute show path

f_midi2_opts_str_show() takes the string lock internally, but its
callers dereference the opts->info.<field> pointer before calling it,
outside the lock. This races with f_midi2_opts_str_store(), which
frees the old string under opts->lock when the attribute is written
concurrently, the show path can read a pointer that gets freed
before the lock inside str_show() is even taken.

Change f_midi2_opts_str_show() to take a pointer to the string field,
matching the existing pattern in f_midi2_opts_str_store(), and
dereference it only after the lock is held. Update all three callers
(iface_name, block name, and the EP string option macro) accordingly.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 29ee7a4dddd5caa18d1cef000f20c6af43f762f1
Version < f9bdf4c4f6410a1dfafafa383a0e21069372657f
Status affected
Version 29ee7a4dddd5caa18d1cef000f20c6af43f762f1
Version < d11f3300b39e2daad2f0d9d66ddcc39a156cb594
Status affected
Version 29ee7a4dddd5caa18d1cef000f20c6af43f762f1
Version < e89e30f0b5d3004fe5955250bd8b04f3733e32ce
Status affected
Version 29ee7a4dddd5caa18d1cef000f20c6af43f762f1
Version < 49fab5e1bdb205c36c965d0e9677bc40d282d3a2
Status affected
Version 29ee7a4dddd5caa18d1cef000f20c6af43f762f1
Version < fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f9bdf4c4f6410a1dfafafa383a0e21069372657f
https://git.kernel.org/stable/c/d11f3300b39e2daad2f0d9d66ddcc39a156cb594
https://git.kernel.org/stable/c/e89e30f0b5d3004fe5955250bd8b04f3733e32ce
https://git.kernel.org/stable/c/49fab5e1bdb205c36c965d0e9677bc40d282d3a2
https://git.kernel.org/stable/c/fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b