CVE-2026-90045: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it while async requests are pending. This can result in a use-after-free if the task exits before completion handling finishes. Take a reference with mmgrab() when queuing the read request and release it with mmdrop() on request completion.
Affected products
- Linux Linux: from 3.15, before 6.12.111 (fixed in 6.12.111); from 6.13, before 6.18.51 (fixed in 6.18.51); from 6.19, before 7.2.5 (fixed in 7.2.5)
Published 2026-09-16. Last modified 2026-09-28.