CVE-2026-68374

Summary

In the Linux kernel, the following vulnerability has been resolved:

usb: core: sysfs: add lock to bos_descriptors_read()

Add a lock to the function bos_descriptors_read().

This function accesses udev->bos, which could be simultaneously freed in usb_reset_and_verify_device(), a function that is commonly called in drivers all over the kernel.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c07caee449c968842a350bfefa049889923b8240affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 217774e143d7b5a88739193284b6421be3978601affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ab82adf5e63b2d89ead7933ab753b9cedbe028e9affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4e0197fbb0eec588795d5431716a244d9ac8fa93affected
LinuxLinux0 < 6.12.101affected
LinuxLinux0 < 6.18.42affected
LinuxLinux0 < 7.1.6affected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References