CVE-2026-90020
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but dev->state is checked after acquiring the lock. Therefore a concurrent bind can change the device state between these operations, which can leave ioctl with a stale NULL gadget pointer and causing a NULL pointer dereference at gadget->ops->ioctl. Read dev->gadget while holding dev->lock so that the gadget pointer and device state are sampled consistently.
Affected versions
Linux kernel versions
2.6.12
and later are affected. Fixed in
5.10.270,
5.15.221,
6.1.188,
6.6.157,
6.12.110,
6.18.51,
7.2.5,
7.3-rc2
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-90020?
CVE-2026-90020 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.12 onward and has been patched in 5.10.270, 5.15.221, 6.1.188 and others. CVE-2026-90020 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-90020?
Yes. CVE-2026-90020 has been patched. Fixed versions include 5.10.270, 5.15.221, 6.1.188 and others. If you are running Linux kernel 2.6.12 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90020 actively exploited?
No. CVE-2026-90020 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.