CVE-2026-64345
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the return…
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the return value. VFS does not call ->release() for a failed open, so every rejected second open permanently leaks one reference. Move kref_get() into the successful-open branch.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/30adce93d5c4a5a1ec29d9249e3fdfcc391d406bPatch
- https://git.kernel.org/stable/c/75c0ad13e136961328253742501b4efc3988a587Patch
- https://git.kernel.org/stable/c/7f1f24c367938c5537e2308bf9a965f051d14774Patch
- https://git.kernel.org/stable/c/8a5eba992c862b0c94411eecf9b7121e8636db38Patch
- https://git.kernel.org/stable/c/94ec20d97aa51547965a539f660a1fe79c6929a3Patch
- https://git.kernel.org/stable/c/bf20c94fa6aaff945f0ae3a23f3212cd299f28d9Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.