CVE-2026-89734
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
In uvcg_video_init(), if kthread_run_worker() fails, the error logged uses uvcg_err(), however, the pointer it uses: video->uvc is not assigned at this point, triggering a null pointer dereference. Fix this by directly using uvc->func which is assigned already.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f0bbfbd16b3b67106535299d6a9ca3a5565494a6 < dbe2762ae8e543b06c57f1ac6512b02fd3fd09b2 | affected |
| Linux | Linux | f0bbfbd16b3b67106535299d6a9ca3a5565494a6 < d511e015d06767f52bb18d48371cab6d7cb88433 | affected |
| Linux | Linux | f0bbfbd16b3b67106535299d6a9ca3a5565494a6 < 5b1da38592efdc1a263d4c0353298cba19e9d6fc | affected |
| Linux | Linux | 6.13 | affected |
| Linux | Linux | 0 < 6.13 | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/dbe2762ae8e543b06c57f1ac6512b02fd3fd09b2
- https://git.kernel.org/stable/c/d511e015d06767f52bb18d48371cab6d7cb88433
- https://git.kernel.org/stable/c/5b1da38592efdc1a263d4c0353298cba19e9d6fc
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.