CVE-2026-64584

Source
https://cve.org/CVERecord?id=CVE-2026-64584
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64584.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64584
Downstream
BELL (1)
DEBIAN (1)
MGASA (2)
openSUSE (2)
SUSE (10)
UBUNTU (1)
Related
Published
2026-08-06T07:06:25Z
Modified
2026-10-08T02:51:32Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
usb: gadget: f_midi: cancel pending IN work before freeing the midi object
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi: cancel pending IN work before freeing the midi object

The f_midi driver embeds a work item (midi->work) whose handler, f_midi_in_work(), dereferences the enclosing struct f_midi through container_of(). This work is armed from two sites: f_midi_complete(), on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA rawmidi output-stream start.

Neither f_midi_disable() nor f_midi_unbind() cancels midi->work. f_midi_disable() only disables the endpoints and drains the in_req_fifo; it does not synchronize the work item, and the sound card is released asynchronously to the final free of the midi object.

The midi object is reference-counted (midi->free_ref) and is freed in f_midi_free() only once both the usb_function reference and the rawmidi private_data reference have been dropped. In f_midi_unbind(), f_midi_disable() runs before the sound card is released, so while the USB endpoints are already disabled the rawmidi device is still usable by an open substream. A concurrent userspace write on such a substream can reach f_midi_in_trigger() and queue midi->work again after f_midi_disable() has returned. A work item armed this way may still be pending when the last reference drops and f_midi_free() proceeds to kfree(midi), letting f_midi_in_work() dereference the struct after it has been freed, a use-after-free.

For this reason cancelling midi->work in f_midi_disable() would not be sufficient: the ALSA trigger path can rearm the work after disable() returns. Cancelling at the refcount-zero free site is the boundary after which neither arming source can survive, because by then both references that keep the midi object alive have been dropped: the USB endpoints are already disabled and the rawmidi device has been released.

Fix this by calling cancel_work_sync(&midi->work) in the refcount-zero block of f_midi_free(), before the embedded work_struct is freed along with the rest of the structure. opts->lock is a sleeping mutex, so calling cancel_work_sync() under it is permitted, and the handler takes midi->transmit_lock rather than opts->lock, so no self-deadlock can occur while it waits for a running instance of the work to finish.

This issue was found by an in-house static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64584.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3635523e9b96213969693c320302d536774d8e9b
Fixed
f3c6f2c38062703d3dc7f86958bb0790c6959add
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8653d71ce3763aedcf3d2331f59beda3fecd79e4
Fixed
df18150126f66817e4d3f79f309e9c92d6ff384e
Fixed
620955b222c47332297d6bf38f78541aa699238a
Fixed
380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9
Fixed
87bc316dd6fc90072297c635e10b9aa6075ecda1
Fixed
f45089eaad0a083d71d84ff175741d7e157d9b69
Fixed
ac9a51d910bb7465c554c45320cb6c09f3d0b49d
Fixed
5650c18d93a1db7e27cb5a40b394747eb4686d5b
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.10.235
Fixed
5.10.265
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.4.291
Fixed
5.5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d

Affected versions

v5.*
v5.10.235
v5.10.236
v5.10.237
v5.10.238
v5.10.239
v5.10.240
v5.10.241
v5.10.242
v5.10.243
v5.10.244
v5.10.245
v5.10.246
v5.10.247
v5.10.248
v5.10.249
v5.10.250
v5.10.251
v5.10.252
v5.10.253
v5.10.254
v5.10.255
v5.10.256
v5.10.257
v5.10.258
v5.10.259
v5.10.260
v5.10.261
v5.10.262
v5.10.263
v5.10.264
v5.4.291
v5.4.292
v5.4.293
v5.4.294
v5.4.295
v5.4.296
v5.4.297
v5.4.298
v5.4.299
v5.4.300
v5.4.301
v5.4.302

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64584.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64584.json"