CVE-2026-64345: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the return value. VFS does not call ->release() for a failed open, so every rejected second open permanently leaks one reference. Move kref_get() into the successful-open branch.

Affected products

  • Linux Linux Kernel: from 4.4.241, before 4.5 (fixed in 4.5); from 4.9.241, before 4.10 (fixed in 4.10); from 4.14.203, before 4.15 (fixed in 4.15); from 4.19.154, before 4.20 (fixed in 4.20); from 5.4.73, before 5.5 (fixed in 5.5); from 5.8.17, before 5.9 (fixed in 5.9); …

Published 2026-07-25. Last modified 2026-09-03.