VDB

CVE-2026-80854

CVE-2026-80854 PUBLISHED

Reported by Linux · Published September 4, 2026

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from the fabric_pre_unlink() callback, before core_dev_del_lun() waits for active se_lun references to drain. If removal of the last LUN races a nexus removal, the latter can observe a zero port count and call target_remove_session(). This frees sess_cmd_map while an in-flight struct usbg_cmd, including its work item, can still be accessed. Overlapping the last-LUN unlink with nexus removal reproduces this lifetime violation as a DEBUG_OBJECTS "free active" warning for usbg_cmd_work, followed by a target-core BUG/Oops. The generic target-core unlink path has no callback after core_dev_del_lun() completes. Add an optional fabric_post_unlink() callback and use it for the f_tcm port count. The count now remains nonzero until core_dev_del_lun() has finished draining active LUN references, preventing nexus removal from freeing the session during command completion.

EPSS 0.18% · 8.0th percentile

Risk Scores

EPSS Score
0.18%
8.0th percentile

Affected Products

VendorProductVersions
LinuxLinuxc52661d60f636d17e26ad834457db333bd1df494, c52661d60f636d17e26ad834457db333bd1df494, c52661d60f636d17e26ad834457db333bd1df494
LinuxLinux3.5, 0, 5.10.269
linuxlinux_kernel3.5, 3.5, 3.5
LinuxLinuxc52661d60f636d17e26ad834457db333bd1df494, c52661d60f636d17e26ad834457db333bd1df494, c52661d60f636d17e26ad834457db333bd1df494

Timeline

  • Sep 4, 2026 Coalition ESS Score
  • Sep 4, 2026 CVE Published
  • Sep 5, 2026 EPSS Score
  • Sep 15, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›