CVE-2026-89738
Received Received - Intake

USB Gadget AT91 UDC Use-After-Free in Polled-VBUS Mode

Vulnerability report for CVE-2026-89738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed In polled-VBUS mode (board.vbus_pin && board.vbus_polled), probe arms a self-restarting cycle: at91_vbus_timer() schedules vbus_timer_work, and at91_vbus_timer_work() calls at91_vbus_update() and re-arms the timer via mod_timer(). Both recover the same udc through container_of and dereference it on every iteration. Neither teardown path cancels this cycle. udc is devm-allocated, so it is freed after at91udc_remove() returns, and is likewise freed when probe fails and devres runs. A timer callback or work item that is pending or running at either point dereferences the freed udc. Add at91_udc_shutdown_vbus_timer() and call it from at91udc_remove() and from the usb_add_gadget_udc() failure path in probe; the remaining probe error paths fail before the timer is armed. timer_shutdown_sync() waits for a running callback and clears timer->function, which makes the work handler's mod_timer() a permanent no-op; cancel_work_sync() then drains any pending or running work whose re-arm attempt now does nothing. The timer must be shut down first, since cancelling the work alone would let the timer re-queue it. The guard mirrors probe: in IRQ mode the timer and work_struct are never initialized. This does not require a fault; a normal driver unbind can interleave with an already queued work item. This issue was found by an in-house static analysis tool.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a use-after-free issue in the AT91 USB device controller (udc) driver. When polled-VBUS mode is enabled, a timer and work queue are set up to monitor VBUS status. However, these are not properly canceled during driver teardown, leading to potential access of freed memory when the udc is removed or probe fails.

Detection Guidance

This vulnerability is specific to the Linux kernel's USB gadget driver for AT91 devices. Detection requires checking kernel logs for errors related to the at91_udc module or USB gadget subsystem. Look for messages about timer or work queue issues during USB gadget unbind or shutdown. No network-specific detection is applicable.

Impact Analysis

This could cause system instability or crashes if the freed udc is accessed by a pending timer or work item. It may also lead to undefined behavior or potential privilege escalation if exploited maliciously.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a low-level kernel driver issue involving a use-after-free condition in the USB gadget subsystem. Compliance impacts would only occur if this flaw led to data corruption, unauthorized access, or service disruption in systems handling sensitive data.

Mitigation Strategies

Update your Linux kernel to a version that includes the fix for this vulnerability. If immediate updating is not possible, avoid unbinding or unloading the at91_udc module while the system is running. Ensure no USB gadget operations are performed during critical system shutdowns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89738. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart