usb: gadget: f_tcm: keep port count until LUN teardown completes

Summary

CVECVE-2026-80854
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-04 16:18:14 UTC
Updated2026-09-04 16:18:14 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from the fabric_pre_unlink() callback, before core_dev_del_lun() waits for active se_lun references to drain. If removal of the last LUN races a nexus removal, the latter can observe a zero port count and call target_remove_session(). This frees sess_cmd_map while an in-flight struct usbg_cmd, including its work item, can still be accessed. Overlapping the last-LUN unlink with nexus removal reproduces this lifetime violation as a DEBUG_OBJECTS "free active" warning for usbg_cmd_work, followed by a target-core BUG/Oops. The generic target-core unlink path has no callback after core_dev_del_lun() completes. Add an optional fabric_post_unlink() callback and use it for the f_tcm port count. The count now remains nonzero until core_dev_del_lun() has finished draining active LUN references, preventing nexus removal from freeing the session during command completion.

Risk And Classification

EPSS: 0.001820000 probability, percentile 0.078380000 (date 2026-09-07)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 c494c5562ca69b61a82f566e3b87a445d2c28929 git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 c1f359d9a5efed458946063de65ddbeaacc4f165 git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 178f59a0bccd3f66cdfa5184310f31a58b7257c4 git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 ad6f0375d2e93a1d8c015463e5e92dfcb26e311b git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 2efbfd42441d3ef8137aff2d59e9835e1d5ae780 git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95 git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 bbd6aa311a9f4dd17822c7557451458d3d2e980b git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 eaa96a8458f54d6cf0954242ab8b1df2a6fccafa git Not specified
CNA Linux Linux affected c52661d60f636d17e26ad834457db333bd1df494 c39d0916da47d94909391876c9e5bd429ea7b1b9 git Not specified
CNA Linux Linux affected 3.5 Not specified
CNA Linux Linux unaffected 3.5 semver Not specified
CNA Linux Linux unaffected 5.10.269 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.220 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.187 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.156 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.108 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.49 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.13 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2.3 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report