Linux kernel USB gadget ffs use-after-free due to missing mm reference
CVE-2026-90045 Published on September 16, 2026
USB: gadget: ffs: fix mm lifetime handling
In the Linux kernel, the following vulnerability has been resolved:
USB: gadget: ffs: fix mm lifetime handling
io_data stores a pointer to the submitting task's mm_struct,
but does not currently hold a reference to it while async
requests are pending.
This can result in a use-after-free if the task exits before
completion handling finishes.
Take a reference with mmgrab() when queuing the read request
and release it with mmdrop() on request completion.
Products Associated with CVE-2026-90045
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below f3d31484b3f26d63c09e5569ebfaa1079a17f171 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 7411de0ce3b45286de1de82526795658ea6eacb0 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 5eb5c72c72fef76cb765ef1669b62b6a3ba1bfc8 is affected.
- Before 6.18.51 is affected.
- Before 7.2.5 is affected.
- Version 6.18.51, <= 6.18.* is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.