-

CVE-2026-90024

usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs

A null-pointer dereference occurs in f_midi2_free_ep_reqs() when attempting
to clean up an endpoint that was never initialized.

When configuring the MIDI 2.0 gadget via configfs and setting the block
direction to SNDRV_UMP_DIR_INPUT, the initialization of the midi1_ep_out
endpoint is explicitly skipped during the gadget bind phase
(f_midi2_bind()). As a result, the usb_ep->card field remains NULL.

Later, when the host sets the alternate setting, f_midi2_set_alt()
unconditionally stops both the IN and OUT endpoints by calling
f_midi2_stop_eps(), which in turn calls f_midi2_free_ep_reqs() for both
endpoints. When f_midi2_free_ep_reqs() is called for the uninitialized
midi1_ep_out, it attempts to dereference usb_ep->card to determine the
number of requests to free, leading to a crash.

Fix this by using usb_ep->num_reqs instead of usb_ep->card->info.num_reqs
in f_midi2_free_ep_reqs(). usb_ep->num_reqs is correctly set during
f_midi2_init_ep() and remains 0 if the endpoint was never initialized,
safely avoiding the loop. For consistency, apply the same change to
f_midi2_alloc_ep_reqs().

Oops: general protection fault, probably for non-canonical address
0xdffffc00000000ee: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000770-0x0000000000000777]
...
RIP: 0010:f_midi2_free_ep_reqs drivers/usb/gadget/function/f_midi2.c:1166
[inline]
RIP: 0010:f_midi2_stop_eps+0x28e/0x4d0
drivers/usb/gadget/function/f_midi2.c:1246
...
Call Trace:
 <TASK>
 f_midi2_set_alt+0x11c/0xf00 drivers/usb/gadget/function/f_midi2.c:1296
 composite_setup+0x1ffd/0x3480 drivers/usb/gadget/composite.c:1933
 configfs_composite_setup+0xbd/0x100 drivers/usb/gadget/configfs.c:1877
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8b645922b22303cec4628dbbbf6c8553d1cdec87
Version < 51ddc55c75087ac25342f6d73d3aeaf14f59bd76
Status affected
Version 8b645922b22303cec4628dbbbf6c8553d1cdec87
Version < 5b92f6a0c7c01efbb335d837ecdf34d38d98720f
Status affected
Version 8b645922b22303cec4628dbbbf6c8553d1cdec87
Version < 9c3d5091e3568ed48ac4c5b08a78eb06fad0d70a
Status affected
Version 8b645922b22303cec4628dbbbf6c8553d1cdec87
Version < 4079f19a0e1ce76f1e21a398f02aca150ceaaf61
Status affected
Version 8b645922b22303cec4628dbbbf6c8553d1cdec87
Version < f0efaf1872949e96d213c8e910fd9517f7d7c406
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/51ddc55c75087ac25342f6d73d3aeaf14f59bd76
https://git.kernel.org/stable/c/5b92f6a0c7c01efbb335d837ecdf34d38d98720f
https://git.kernel.org/stable/c/9c3d5091e3568ed48ac4c5b08a78eb06fad0d70a
https://git.kernel.org/stable/c/4079f19a0e1ce76f1e21a398f02aca150ceaaf61
https://git.kernel.org/stable/c/f0efaf1872949e96d213c8e910fd9517f7d7c406