CVE-2026-93121 PUBLISHED

usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths

Assigner: Linux
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths

The error paths for endpoint-disabled (ESHUTDOWN) and request-allocation failure (ENOMEM) in ffs_dmabuf_transfer() jump to err_fence_put which calls dma_fence_put() on the fence. However, at that point the fence has only been kmalloc'd — dma_fence_init() has not been called yet, so the refcount and the fence ops are uninitialized. Calling dma_fence_put() on such an object leads to undefined behavior.

Use kfree() instead, since the fence is just a plain allocation at this stage, and rename the label to err_fence_free to reflect the actual cleanup action.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 7b07a2a7ca02a20124b552be96c5a56910795488 to be539138d9a187af3b884525a395db10797c64f1 (excl.)
  • affected from 7b07a2a7ca02a20124b552be96c5a56910795488 to 5fd8baacc7dc477df9cac61b45491840247a9b1e (excl.)
  • affected from 7b07a2a7ca02a20124b552be96c5a56910795488 to 58952c83dfe6ea3294a74734d2d1018c1120779a (excl.)
  • affected from 7b07a2a7ca02a20124b552be96c5a56910795488 to 621707dc67c9846fd876d7579ec951d92aa033f1 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.9 is affected
  • unaffected from 0 to 6.9 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References