PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64242 Linux CVE debrief

A double-free vulnerability was found in the Linux kernel's usb gadget driver for net2280 devices. When the probe function encounters an error, it calls net2280_remove(), which drops the gadget reference with usb_put_gadget(). However, the explicit kfree(dev) call afterwards can free the same object again, leading to a double-free issue. This vulnerability affects Linux kernel versions 5.10 to 5.10.259, 5.11 to 5.15.210, 5.16 to 6.1.176, 6.2 to 6.6.143, 6.7 to 6.12.93, 6.13 to 6.18.35, 6.19 to 7.0.12, and 7.1 rc1 to rc5. The vulnerability was found by a static analysis tool. To verify, defenders should review Linux kernel version usage and check for updates or patches from the Linux kernel stable branch. The issue can be fixed by removing the explicit kfree() call and letting the gadget device release callback handle the final free. Linux kernel developers, Linux system administrators, and users of Linux-based systems, especially those using net2280 devices, should review and apply patches or mitigations to prevent potential double-free vulnerabilities.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-08-13
Advisory published
2026-07-24
Advisory updated
2026-08-13

Who should care

Linux kernel developers, Linux system administrators, and users of Linux-based systems, especially those using net2280 devices, should review and apply patches or mitigations to prevent potential double-free vulnerabilities. Security teams and vulnerability management teams should prioritize patching and monitor for suspicious usb gadget activity. Additionally, operators and platform administrators should assess their exposure and implement compensating controls if necessary. Security teams should also track exceptions and retest remediated assets to ensure the vulnerability is properly addressed. Linux-based system users should stay informed about updates and patches for their specific Linux kernel versions. Those responsible for Linux kernel development and maintenance should prioritize resolving this issue and testing for similar vulnerabilities in the future. Linux distribution maintainers should also verify and update their packages accordingly. Finally, security researchers should continue to investigate and disclose similar issues to improve the security of the Linux kernel and related components. The vulnerability's impact on various Linux kernel versions and the difficulty in detecting it make it essential for a wide range of stakeholders to take action. Linux users and administrators should verify their kernel versions and stay up-to-date with the latest security patches to mitigate this vulnerability effectively. Linux distributions should also ensure that their packages are updated and patched accordingly. By taking these steps, Linux kernel developers, administrators, and users can work together to prevent potential attacks and improve the overall security of Linux-based systems. Linux kernel developers should also review their code and testing procedures to prevent similar issues in the future. Linux system administrators should prioritize patching and implement additional security measures, such as monitoring and compensating controls, to protect their systems from potential attacks. Users of Linux-based systems should also be aware of the vulnerability and take steps to protect themselves, such as keeping their systems up-to-date and informed. By

Technical summary

The Linux kernel's usb gadget driver for net2280 devices has a double-free vulnerability. When the probe function encounters an error, it calls net2280_remove(), which drops the gadget reference with usb_put_gadget(). However, the explicit kfree(dev) call afterwards can free the same object again, leading to a double-free issue. This can be fixed by removing the explicit kfree() call and letting the gadget device release callback handle the final free.

Defensive priority

High

Recommended defensive actions

  • Apply patches from Linux kernel stable branch
  • Inventory Linux systems for net2280 gadget usage
  • Monitor for suspicious usb gadget activity
  • Restrict access to vulnerable Linux kernel versions
  • Update Linux kernel to version 5.10.260 or later, 5.15.211 or later, 6.1.177 or later, 6.6.144 or later, 6.7 or later, 6.12.94 or later, 6.18.36 or later, 7.0.13 or later

Evidence notes

The vulnerability was found by a static analysis tool. The affected Linux kernel versions are 5.10 to 5.10.259, 5.11 to 5.15.210, 5.16 to 6.1.176, 6.2 to 6.6.143, 6.7 to 6.12.93, 6.13 to 6.18.35, 6.19 to 7.0.12, and 7.1 rc1 to rc5. To verify, defenders should review Linux kernel version usage and check for updates or patches from the Linux kernel stable branch.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64242 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64242

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64242 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64242

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/085652fda7f38040d1a2c42d72614f418feb843f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/48f89ead20e48d447ad29fa937b43b9fa981cf28

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/550fa4d071a8c8e53072900869d37ae6abf4999d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/71b3391dc81655ff058492f8e9d013b2c6e5747b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c5b9fdb1e8ddf50bc6272927edb118679f170350

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c8547c74988e0b5f4cbb1b895e2a57aae084f070

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/db2b72e83a0208ae2b3b270bf91662b1c6849a9b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.