CVE-2026-90019
Last modified
CVE-2026-90019 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: gadget: fix null pointer dereference in usb_put_function_instance() usb_put_function_instance() attempts to dereference fd inside fi struct to get mod in uvc_alloc_inst() error path. However, fd is not allocated until later in try_get_usb_function_instance() after allocating fi in uvc_alloc_inst() and thus guranteed to be null in error path.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: fix null pointer dereference in usb_put_function_instance() usb_put_function_instance() attempts to dereference fd inside fi struct to get mod in uvc_alloc_inst() error path. However, fd is not allocated until later in try_get_usb_function_instance() after allocating fi in uvc_alloc_inst() and thus guranteed to be null in error path. Fix this by adding a null check for fi->fd that returns if fd is null.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 0fc54a00954f9f4c3e3d4ffa64a530685d99a39b; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 6e6736c049683380f5e20becde498986e9293ca4; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 3a9691fff79bcce95338435599df6d3ae433cfdc; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 7a4f4ca7ff32ae24807c83e2a06d62b13378d53c; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 6ea3a073ca97716d4a73df49a3bec1c3ccf8e2a0; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < d3a7fa61997db3bf6dadef4c1bd87a4fa782a817; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 5117f236e9e30744338b425395d55913c4500897; >= 0062f6e56f70bd2230ba1ebd1667d1b32a1af3b2, < 6e74ac5c596fd246e37eadfc354567179ccbe9aa |
| Linux | Linux | 3.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90019?
How severe is CVE-2026-90019?
How do I fix CVE-2026-90019?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90013In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90014In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90015In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90016In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-90017In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-90018In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-9002IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could al…6.5
- CVE-2026-90020In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90021In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90022In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90023In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90024In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90019?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
