PT-2026-93665 · Linux · Linux Kernel

CVE-2026-90024

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null-pointer dereference occurs in the f midi2 free ep reqs() function when cleaning up an endpoint that was not initialized. This happens when the MIDI 2.0 gadget is configured via configfs with the block direction set to SNDRV UMP DIR INPUT, causing the midi1 ep out endpoint initialization to be skipped during the f midi2 bind() phase. Consequently, the usb ep->card field remains NULL. When the host sets an alternate setting, f midi2 set alt() calls f midi2 stop eps(), which then triggers f midi2 free ep reqs(). The function attempts to dereference usb ep->card to determine the number of requests to free, resulting in a system crash.
Recommendations Update the Linux kernel to a version where f midi2 free ep reqs() and f midi2 alloc ep reqs() use usb ep->num reqs instead of usb ep->card->info.num reqs.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101288
CVE-2026-90024
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel