CVE-2026-89739
Received Received - Intake

Race Condition Leading to Use-After-Free in Linux Kernel USB DWC3 Gadget

Vulnerability report for CVE-2026-89739, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition In dwc3_gadget_init_endpoint, &dep->nostream_work is bound with dwc3_nostream_work, and dwc3_gadget_endpoint_stream_event can queue this delayed work on system_percpu_wq when a DEPEVT_STREAM_NOSTREAM event is received. If we remove the gadget, dwc3_gadget_free_endpoints makes cleanup and the memory allocated for dep with kzalloc() is released by kfree(dep), while the delayed work mentioned above may still be pending or running. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | dwc3_thread_interrupt | dwc3_endpoint_interrupt | dwc3_gadget_endpoint_stream_event | queue_delayed_work(system_percpu_wq, | &dep->nostream_work) dwc3_gadget_free_endpoints | dwc3_free_trb_pool(dep) | list_del(&dep->endpoint.ep_list) | dwc3_debugfs_remove_endpoint_dir(dep) | kfree(dep) | // dep is freed | | dwc3_nostream_work | // use dep (use-after-free) Fix it by canceling the delayed work before kfree(dep) in dwc3_gadget_free_endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's USB gadget driver for the DesignWare USB3 controller (dwc3). It occurs due to a race condition where a delayed work item (nostream_work) may still be running after the memory it references (dep) has been freed. The issue stems from not properly canceling the work item before freeing the associated endpoint structure.

Detection Guidance

This vulnerability is specific to the Linux kernel's USB gadget subsystem (dwc3). Detection requires checking kernel logs for use-after-free errors related to dwc3 or USB gadget operations. Monitor system logs for crashes or warnings during USB gadget operations. No network-specific detection commands are applicable.

Impact Analysis

This vulnerability could lead to system crashes, memory corruption, or potential privilege escalation if exploited. Systems using affected Linux kernel versions with USB gadget functionality enabled may be vulnerable to denial-of-service attacks or other malicious activities.

Compliance Impact

This vulnerability is a use-after-free bug in the Linux kernel's USB gadget subsystem, which could lead to memory corruption or crashes. It does not directly impact compliance with standards like GDPR or HIPAA, as those focus on data protection and privacy rather than kernel memory safety issues.

Mitigation Strategies

Update your Linux kernel to the latest patched version that includes the fix for CVE-2026-89739. If immediate patching is not possible, avoid using USB gadget functionality until the update is applied to prevent potential use-after-free issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89739. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart