What is CVE-2026-64233?
This vulnerability in the Linux kernel USB gadget UVC subsystem arises from a race condition when walking extension_units without holding opts->lock. A local attacker could exploit this to trigger a use-after-free or data leak, requiring affected systems to apply kernel patches.
Azərbaycanca: Linux kernel USB gadget UVC alt-sistemində aşkarlanan bu boşluq, opts->lock tutulmadan extension_units siyahısı üzərində gəzinti nəticəsində yaranan yarış şəraiti (race condition) zəifliyidir. Yerli təcavüzkar istismar yolu ilə istifadədən-sonra-sərbəst buraxma (use-after-free) və ya məlumat sızmasına səbəb ola bilər, təsirlənmiş sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
In which Linux kernel subsystem was CVE-2026-64233 discovered?
This vulnerability was discovered in the USB gadget UVC subsystem of the Linux kernel.
What are the potential consequences of exploiting CVE-2026-64233?
When exploited by a local attacker, this vulnerability can result in a use-after-free condition or a data leak.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.