PT-2026-93532 · Linux · Linux Kernel

CVE-2026-89891

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the em28xx driver. When a device with has dual ts=1 is probed and the is audio only path is taken, both dev and dev->dev next are added to the global em28xx devlist via the em28xx init extension() function. During disconnection, the em28xx close extension(dev) function only removes dev->devlist from the list, leaving dev->dev next->devlist linked. When dev next is freed via kref put(), it creates a dangling pointer in em28xx devlist. Subsequent device probes calling em28xx init extension() can then trigger a list corruption bug when list add tail() detects the freed node.
Recommendations As a temporary mitigation, restrict the use of devices that trigger the is audio only and has dual ts code paths in the em28xx driver. Update the Linux kernel to a version where the em28xx close extension() function is updated to remove dev->dev next->devlist from the global list before the device is freed.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101504
CVE-2026-89891
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel