CVE-2026-72079

Source
https://cve.org/CVERecord?id=CVE-2026-72079
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72079.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72079
Downstream
Published
2026-08-15T05:52:29.096Z
Modified
2026-08-18T03:31:30.111695690Z
Summary
Input: ims-pcu - fix use-after-free and double-free in disconnect
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: ims-pcu - fix use-after-free and double-free in disconnect

imspcudisconnect() only intended to perform cleanup when the primary (control) interface is unbound. However, it currently relies on the interface class to distinguish between control and data interfaces. A malicious device could present a data interface with the same class as the control interface, leading to premature cleanup and potential use-after-free or double-free.

Switch to verifying that the interface being disconnected is indeed the control interface.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72079.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
628329d52474323938a03826941e166bc7c8eff4
Fixed
315f269ea04bc1477ab9bf351e939623d12a1621
Fixed
293388e42e5c0865204de6f36bfb8662156fce3b
Fixed
921abbb33887052e46b1b77299f87a3c741dc580
Fixed
6a6c373e6a82eddc522342c8a8db7072c65f2b56
Fixed
a4b3f4d42fbf58f06f0d49e37a9d0d9392eca338
Fixed
6aacc18004b1a915ccb8a829d30279a37988066e
Fixed
bf0b58ba489d0bdaa18c7dd8beeaeb954dd7dbb7
Fixed
462a999917755a3bf77448dfd64307963cf0a9f0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72079.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72079.json"