CVE-2026-90029

Unknown

Last modified

CVE-2026-90029 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disconnect realtek_cr_destructor() calls timer_delete() before the chip containing the timer is freed. The timer callback may still be running and can rearm itself, resulting in a use-after-free. Use timer_shutdown_sync() to wait for the callback and prevent further rearming.

Description

In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disconnect realtek_cr_destructor() calls timer_delete() before the chip containing the timer is freed. The timer callback may still be running and can rearm itself, resulting in a use-after-free. Use timer_shutdown_sync() to wait for the callback and prevent further rearming. Do this unconditionally because ss_en may be changed after the timer is armed. Move timer_setup() into init_realtek_cr() so the timer is initialized before any failure path can invoke the destructor. Found by static analysis.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= e931830bb877e2aad9a1be83506f9bdb26c91e4e, < 7c4e2f964c65dea4ea22386799d5fb10ef1e3e54; >= e931830bb877e2aad9a1be83506f9bdb26c91e4e, < cae9dbba6adae21a04a3bd045e07b489847ff2c6; >= e931830bb877e2aad9a1be83506f9bdb26c91e4e, < 4ffee1aebb0c0ffcda9faffd17834ea9b00d42cc
LinuxLinux3.1

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90029?
In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disconnect realtek_cr_destructor() calls timer_delete() before the chip containing the timer is freed. The timer callback may still be running and can rearm itself, resulting in a use-after-free. Use timer_shutdown_sync() to wait for the callback and prevent further rearming. Do this unconditionally because ss_en may be changed after the timer is armed. Move timer_setup() into init_realtek_cr() so the timer is initialized before any failure path can invoke the destructor. Found by static analysis.
How severe is CVE-2026-90029?
Severity scoring for CVE-2026-90029 is pending analysis.
How do I fix CVE-2026-90029?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90029?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST