PT-2026-27685 · Linux · Linux Kernel

CVE-2026-23320

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v3.1

5.8

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel’s Network Controller Multiplexer (NCM) gadget driver has an issue where the lifecycle of the network device is not correctly aligned with the USB connection’s bind and unbind operations. Currently, the network device is allocated during configuration instance allocation and freed during instance deallocation, rather than being tied to the USB connection. This decoupling can lead to two problems: a NULL pointer dereference upon USB disconnection and dangling sysfs symbolic links. The issue occurs because the network device can outlive its parent device when the USB gadget is disconnected. The fix involves moving the network device allocation to the bind function and deallocation to the unbind function, ensuring the network interface exists only when the gadget function is bound to a configuration. To support pre-bind configuration, user-provided options are cached and applied to the network device upon creation. The fix also preserves a use-after-free fix from a previous commit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12461
CVE-2026-23320

Affected Products

Linux Kernel