PT-2026-93532 · Linux · Linux Kernel
CVE-2026-89891
·
Published
2026-09-16
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the em28xx driver. When a device with
has dual ts=1 is probed and the is audio only path is taken, both dev and dev->dev next are added to the global em28xx devlist via the em28xx init extension() function. During disconnection, the em28xx close extension(dev) function only removes dev->devlist from the list, leaving dev->dev next->devlist linked. When dev next is freed via kref put(), it creates a dangling pointer in em28xx devlist. Subsequent device probes calling em28xx init extension() can then trigger a list corruption bug when list add tail() detects the freed node.Recommendations
As a temporary mitigation, restrict the use of devices that trigger the
is audio only and has dual ts code paths in the em28xx driver. Update the Linux kernel to a version where the em28xx close extension() function is updated to remove dev->dev next->devlist from the global list before the device is freed.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel