CVE-2026-90021

Source
https://cve.org/CVERecord?id=CVE-2026-90021
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90021.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90021
Downstream
Related
Published
2026-09-16T10:33:25Z
Modified
2026-10-08T02:53:15Z
Summary
usb: gadget: f_midi: initialize work in f_midi_alloc()
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi: initialize work in f_midi_alloc()

f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi_register_card(). f_midi_register_card() is only called in f_midi_bind() which actually performs INIT_WORK. If f_midi_bind() is never run, work is not initialized and the if condition in f_midi_free becomes true, this results in a warning later in __flush_work as work->func = 0. Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90021.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8653d71ce3763aedcf3d2331f59beda3fecd79e4
Fixed
3d8b11255e632170f32f1925bfcaf96331f36317
Fixed
02ac76f27db23ef652358458c272d9d2d6f51167
Fixed
858576de6b2f5166b08dae803f0fd0766dcb3002
Fixed
7e07d3e4c389217d7d7171d80edf2e23ac70f1ea
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.4.291
Fixed
5.5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.10.235
Fixed
5.11
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3635523e9b96213969693c320302d536774d8e9b

Affected versions

v5.*
v5.10.235
v5.10.236
v5.10.237
v5.10.238
v5.10.239
v5.10.240
v5.10.241
v5.10.242
v5.10.243
v5.10.244
v5.10.245
v5.10.246
v5.10.247
v5.10.248
v5.10.249
v5.10.250
v5.10.251
v5.10.252
v5.10.253
v5.10.254
v5.10.255
v5.10.256
v5.10.257
v5.10.258
v5.10.259
v5.10.260
v5.10.261
v5.10.262
v5.10.263
v5.10.264
v5.10.265
v5.10.266
v5.10.267
v5.10.268
v5.10.269
v5.10.270
v5.10.271
v5.4.291
v5.4.292
v5.4.293
v5.4.294
v5.4.295
v5.4.296
v5.4.297
v5.4.298
v5.4.299
v5.4.300
v5.4.301
v5.4.302

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90021.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90021.json"