CVE-2026-80854
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_tcm: keep port count until LUN teardown completes
tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from the fabric_pre_unlink() callback, before core_dev_del_lun() waits for active se_lun references to drain.
If removal of the last LUN races a nexus removal, the latter can observe a zero port count and call target_remove_session(). This frees sess_cmd_map while an in-flight struct usbg_cmd, including its work item, can still be accessed.
Leer descripción completaMostrar menos
Overlapping the last-LUN unlink with nexus removal reproduces this lifetime violation as a DEBUG_OBJECTS "free active" warning for usbg_cmd_work, followed by a target-core BUG/Oops.
The generic target-core unlink path has no callback after core_dev_del_lun() completes. Add an optional fabric_post_unlink() callback and use it for the f_tcm port count. The count now remains nonzero until core_dev_del_lun() has finished draining active LUN references, preventing nexus removal from freeing the session during command completion.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4
- https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780
- https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95
- https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b
- https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b
- https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165
- https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9
- https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929
- https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80854",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "c494c5562ca69b61a82f566e3b87a445d2c28929",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "c1f359d9a5efed458946063de65ddbeaacc4f165",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "178f59a0bccd3f66cdfa5184310f31a58b7257c4",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "ad6f0375d2e93a1d8c015463e5e92dfcb26e311b",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "2efbfd42441d3ef8137aff2d59e9835e1d5ae780",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "bbd6aa311a9f4dd17822c7557451458d3d2e980b",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "eaa96a8458f54d6cf0954242ab8b1df2a6fccafa",
"versionType": "git"
},
{
"status": "affected",
"version": "c52661d60f636d17e26ad834457db333bd1df494",
"lessThan": "c39d0916da47d94909391876c9e5bd429ea7b1b9",
"versionType": "git"
}
],
"programFiles": [
"drivers/target/target_core_fabric_configfs.c",
"drivers/usb/gadget/function/f_tcm.c",
"include/target/target_core_fabric.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.5"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/target/target_core_fabric_configfs.c",
"drivers/usb/gadget/function/f_tcm.c",
"include/target/target_core_fabric.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T16:18:14.353",
"references": [
{
"url": "https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: keep port count until LUN teardown completes\n\ntcm_usbg_drop_nexus() permits session removal once tpg_port_count\nreaches zero. However, usbg_port_unlink() currently decrements that\ncount from the fabric_pre_unlink() callback, before core_dev_del_lun()\nwaits for active se_lun references to drain.\n\nIf removal of the last LUN races a nexus removal, the latter can observe\na zero port count and call target_remove_session(). This frees\nsess_cmd_map while an in-flight struct usbg_cmd, including its work item,\ncan still be accessed.\n\nOverlapping the last-LUN unlink with nexus removal reproduces this\nlifetime violation as a DEBUG_OBJECTS \"free active\" warning for\nusbg_cmd_work, followed by a target-core BUG/Oops.\n\nThe generic target-core unlink path has no callback after\ncore_dev_del_lun() completes. Add an optional fabric_post_unlink()\ncallback and use it for the f_tcm port count. The count now remains\nnonzero until core_dev_del_lun() has finished draining active LUN\nreferences, preventing nexus removal from freeing the session during\ncommand completion."
}
],
"lastModified": "2026-09-04T16:18:14.353",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}