CVE-2026-89733: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() In uvc_function_bind() error path, we use usb_ep_free_request which uses uvc->control_req but does not set it to NULL afterwards. Thus, uvc->control_req is a dangling pointer causing a UAF. Also we do not set the uvc->control_buf pointer to NULL after freeing it, which is another dangling pointer. Fix it by setting uvc->control_req to NULL after we run usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the same for uvc_function_unbind().

Affected products

  • Linux Linux: from 3.2.36, before 3.3 (fixed in 3.3); from 3.4.25, before 3.5 (fixed in 3.5); from 3.7.2, before 3.8 (fixed in 3.8); from 3.8, before 5.10.270 (fixed in 5.10.270); from 5.11, before 5.15.221 (fixed in 5.15.221); from 5.16, before 6.1.188 (fixed in 6.1.188); …

Published 2026-09-11. Last modified 2026-09-14.