What is CVE-2026-64242?
This vulnerability in the Linux kernel's USB gadget driver (net2280) leads to a double free condition in the probe error path due to the gadget_release callback. This can cause system instability or potential privilege escalation. Affected systems should apply the available kernel updates.
Azərbaycanca: Linux kernel-də USB gadget driver (net2280) üçün aşkar edilmiş zəiflikdir. Probe xətası zamanı `gadget_release` callback səbəbindən yaddaşın iki dəfə azad edilməsi (`double free`) baş verir ki, bu da sistemin qeyri-sabit işləməsinə və ya imtiyaz artımına səbəb ola bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which component does CVE-2026-64242 affect in the Linux kernel?
The vulnerability affects the net2280 component of the USB gadget driver.
What is the cause of CVE-2026-64242?
The cause is a double free condition in the probe error path due to the gadget_release callback.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.