CVE-2026-90020
Published Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but dev->state is checked after acquiring the lock. Therefore a concurrent bind can change the device state between these operations, which can leave ioctl with a stale NULL gadget pointer and causing a NULL pointer dereference at gadget->ops->ioctl. Read dev->gadget while holding dev->lock so that the gadget pointer and device state are sampled consistently.
Is your site exposed to CVE-2026-90020?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/162178ca83c3de986900385a0477eb539f8e1a7e
https://git.kernel.org/stable/c/64ec019bf9a8b12f53b9f2777d65aadb730b5a84
https://git.kernel.org/stable/c/87cbf9410b12f5c2d659bb01e8ecf6517cb9f28c
https://git.kernel.org/stable/c/8be30959be31b4205e3bdd2e2a6221f3a2ee7ea1
https://git.kernel.org/stable/c/c29a83c1ff3f06d5751f6d365b606c9f81ccc4cb
https://git.kernel.org/stable/c/dd0eed9e165b1a6292f49e622e3dd0b7d99b106d
https://git.kernel.org/stable/c/e8219accce2f6d3502ed71f5b5e854ecf27249a6
https://git.kernel.org/stable/c/ebd916fdfefaacbc0e577f7037ec96b31a105e5f
Frequently Asked Questions
What is CVE-2026-90020? +
In the Linux kernel, the following vulnerability has been resolved:
USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but
dev->state is checked after acquiring the lock. Therefore a concurrent
bind can change the device state between these operations, which can
leave ioctl with a stale NULL gadget pointer and causing a NULL pointer
dereference at gadget->ops->ioctl.
Read dev->gadget while holding dev->lock so that the gadget pointer
and device state are sampled consistently.
How do I check if I'm vulnerable to CVE-2026-90020? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.