← All Advisories

CVE-2026-89739

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89739

Key Details

CVECVE-2026-89739
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition

In dwc3_gadget_init_endpoint, &dep->nostream_work is bound with

dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue

this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM

event is received.

If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and

the memory allocated for dep with kzalloc() is released by kfree(dep),

while the delayed work mentioned above may still be pending or

running. The sequence of operations that may lead to a UAF bug is as

follows:

CPU0 CPU1

| dwc3_thread_interrupt

| dwc3_endpoint_interrupt

| dwc3_gadget_endpoint_stream_event

| queue_delayed_work(system_percpu_wq,

| &dep->nostream_work)

dwc3_gadget_free_endpoints |

dwc3_free_trb_pool(dep) |

list_del(&dep->endpoint.ep_list) |

dwc3_debugfs_remove_endpoint_dir(dep) |

kfree(dep) |

// dep is freed |

| dwc3_nostream_work

| // use dep (use-after-free)

Fix it by canceling the delayed work before kfree(dep) in

dwc3_gadget_free_endpoints. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89739
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89739