CVE-2026-90019
Published Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: fix null pointer dereference in usb_put_function_instance() usb_put_function_instance() attempts to dereference fd inside fi struct to get mod in uvc_alloc_inst() error path. However, fd is not allocated until later in try_get_usb_function_instance() after allocating fi in uvc_alloc_inst() and thus guranteed to be null in error path. Fix this by adding a null check for fi->fd that returns if fd is null.
Is your site exposed to CVE-2026-90019?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0fc54a00954f9f4c3e3d4ffa64a530685d99a39b
https://git.kernel.org/stable/c/3a9691fff79bcce95338435599df6d3ae433cfdc
https://git.kernel.org/stable/c/5117f236e9e30744338b425395d55913c4500897
https://git.kernel.org/stable/c/6e6736c049683380f5e20becde498986e9293ca4
https://git.kernel.org/stable/c/6e74ac5c596fd246e37eadfc354567179ccbe9aa
https://git.kernel.org/stable/c/6ea3a073ca97716d4a73df49a3bec1c3ccf8e2a0
https://git.kernel.org/stable/c/7a4f4ca7ff32ae24807c83e2a06d62b13378d53c
https://git.kernel.org/stable/c/d3a7fa61997db3bf6dadef4c1bd87a4fa782a817
Frequently Asked Questions
What is CVE-2026-90019? +
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: fix null pointer dereference in usb_put_function_instance()
usb_put_function_instance() attempts to dereference fd inside fi struct
to get mod in uvc_alloc_inst() error path. However, fd is not allocated
until later in try_get_usb_function_instance() after allocating fi in
uvc_alloc_inst() and thus guranteed to be null in error path. Fix this
by adding a null check for fi->fd that returns if fd is null.
How do I check if I'm vulnerable to CVE-2026-90019? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.