What is CVE-2026-68456?
This vulnerability exists in the "ueagle-atm" USB modem driver in the Linux kernel. The driver does not wait for pre-firmware loading to complete in the .probe() stage, and the .disconnect() function also fails to account for this completion; if the device is unplugged, used resources are not freed. Affected systems should apply a kernel update.
Azərbaycanca: Bu zəiflik Linux kernel-də "ueagle-atm" USB modem sürücüsündə aşkarlanıb. Cihaz .probe() mərhələsində pre-firmware yüklənməsini gözləmir, .disconnect() funksiyasında da bu tamamlanma nəzərə alınmır; cihaz qoşulmadan çıxarıldıqda istifadə olunan resurslar sərbəst buraxılmır. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
FAQ2
Which component of the Linux kernel contains the CVE-2026-68456 vulnerability?
This vulnerability exists in the "ueagle-atm" USB modem driver in the Linux kernel.
What is the root cause of the CVE-2026-68456 vulnerability?
The driver does not wait for pre-firmware loading to complete in the .probe() stage, and the .disconnect() function also fails to account for this, so resources are not freed when the device is unplugged.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.