usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
Summary
| CVE | CVE-2026-31727 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-01 15:16:35 UTC |
| Updated | 2026-06-19 13:16:27 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo Commit ec35c1969650 ("usb: gadget: f_ncm: Fix net_device lifecycle with device_move") reparents the gadget device to /sys/devices/virtual during unbind, clearing the gadget pointer. If the userspace tool queries on the surviving interface during this detached window, this leads to a NULL pointer dereference. Unable to handle kernel NULL pointer dereference Call trace: eth_get_drvinfo+0x50/0x90 ethtool_get_drvinfo+0x5c/0x1f0 __dev_ethtool+0xaec/0x1fe0 dev_ethtool+0x134/0x2e0 dev_ioctl+0x338/0x560 Add a NULL check for dev->gadget in eth_get_drvinfo(). When detached, skip copying the fw_version and bus_info strings, which is natively handled by ethtool_get_drvinfo for empty strings. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.000180000 probability, percentile 0.046430000 (date 2026-05-05)
Problem Types: CWE-476
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 7c97366f5dac5255e60a317ffe3a5b18f3745547 f9f987472f4b8ab177be2b6492a59278ed969479 git | Not specified |
| CNA | Linux | Linux | affected 36c41e9724c9a7a7cda37f5a4e9d94f25c8031c4 7fce959e9be3bf63bb0fdf4b05f9cc42cb289fe2 git | Not specified |
| CNA | Linux | Linux | affected 93f116c3393a22acab96ad1bef12b2572eb80ca4 0326429e8ba99892e1d1e115dc8e88e1a3b64e24 git | Not specified |
| CNA | Linux | Linux | affected e584cb58a2ea7ff4d3a4bc43d5ca512ed3ecb77d a36e5e800b9c93e3e1ffa42f34d38b36775dbcee git | Not specified |
| CNA | Linux | Linux | affected 85acaba2f42b557499bab3608307f17bf13beb69 7de4d46be40738c7e48e64b5cc0a34aa1e047b0a git | Not specified |
| CNA | Linux | Linux | affected ec35c1969650e7cb6c8a91020e568ed46e3551b0 e002e92e88e12457373ed096b18716d97e7bbb20 git | Not specified |
| CNA | Linux | Linux | affected 6.12.78 6.12.81 semver | Not specified |
| CNA | Linux | Linux | affected 6.18.19 6.18.22 semver | Not specified |
| CNA | Linux | Linux | affected 6.19.9 6.19.12 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/0326429e8ba99892e1d1e115dc8e88e1a3b64e24 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/e002e92e88e12457373ed096b18716d97e7bbb20 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/a36e5e800b9c93e3e1ffa42f34d38b36775dbcee | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f9f987472f4b8ab177be2b6492a59278ed969479 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7de4d46be40738c7e48e64b5cc0a34aa1e047b0a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/7fce959e9be3bf63bb0fdf4b05f9cc42cb289fe2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.