usb: gadget: f_midi: initialize work in f_midi_alloc()

Summary

CVECVE-2026-90021
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-16 11:17:15 UTC
Updated2026-09-16 11:17:15 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi_register_card(). f_midi_register_card() is only called in f_midi_bind() which actually performs INIT_WORK. If f_midi_bind() is never run, work is not initialized and the if condition in f_midi_free becomes true, this results in a warning later in __flush_work as work->func = 0. Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 8653d71ce3763aedcf3d2331f59beda3fecd79e4 3d8b11255e632170f32f1925bfcaf96331f36317 git Not specified
CNA Linux Linux affected 8653d71ce3763aedcf3d2331f59beda3fecd79e4 02ac76f27db23ef652358458c272d9d2d6f51167 git Not specified
CNA Linux Linux affected 8653d71ce3763aedcf3d2331f59beda3fecd79e4 858576de6b2f5166b08dae803f0fd0766dcb3002 git Not specified
CNA Linux Linux affected 8653d71ce3763aedcf3d2331f59beda3fecd79e4 7e07d3e4c389217d7d7171d80edf2e23ac70f1ea git Not specified
CNA Linux Linux affected 89019ab7a64fcdf98a2ba7799e5c6aff58d4a05d git Not specified
CNA Linux Linux affected 3635523e9b96213969693c320302d536774d8e9b git Not specified
CNA Linux Linux affected 5.4.291 5.5 semver Not specified
CNA Linux Linux affected 5.10.235 5.11 semver Not specified
CNA Linux Linux affected 5.12 Not specified
CNA Linux Linux unaffected 5.12 semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.51 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.5 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/02ac76f27db23ef652358458c272d9d2d6f51167 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3d8b11255e632170f32f1925bfcaf96331f36317 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7e07d3e4c389217d7d7171d80edf2e23ac70f1ea 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/858576de6b2f5166b08dae803f0fd0766dcb3002 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report