CVE-2026-93117
In the Linux kernel, the following vulnerability has been resolved: usb: fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when usb_dynids_lock is held, as remove_id_store can free the node. Thus, make a copy in usb_probe_interface. Clarify the documentation that the id parameter is only valid during the probe. USB serial has the same pattern, but it does not need fixing as the IDs cannot be removed via sysfs.
Affected versions
Linux kernel versions
2.6.33
and later are affected. Fixed in
6.1.188,
6.6.157,
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
6 totalFrequently asked questions
-
What is CVE-2026-93117?
CVE-2026-93117 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.33 onward and has been patched in 6.1.188, 6.6.157, 6.12.110 and others. CVE-2026-93117 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-93117?
Yes. CVE-2026-93117 has been patched. Fixed versions include 6.1.188, 6.6.157, 6.12.110 and others. If you are running Linux kernel 2.6.33 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-93117 actively exploited?
No. CVE-2026-93117 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.