CVE-2026-31722 Details
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks: console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -> /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering. To maintain compatibility with legacy composite drivers (e.g., multi.c), the borrowed_net flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.
A vulnerability exists in the Linux kernel's USB gadget function for RNDIS (Remote Network Driver Interface Specification) that relates to the management of the net_device lifecycle. When the RNDIS function is unbound from its parent gadget device, the net_device remains active, leading to dangling symlinks in the sysfs. This issue can cause confusion and potential errors in device management, as the system believes the device is still present when it has been removed. The vulnerability arises because the net_device is not properly reparented during the unbinding process, which is crucial for maintaining an accurate representation of device states and ensuring proper power management.
The vulnerability has been addressed by modifying the RNDIS gadget function to use the device_move() function. This change reparents the net_device between the gadget device tree and the virtual device tree during the bind and unbind cycles, ensuring that the sysfs topology is correct and that power management is handled properly.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/18ada801899f2b13ef0ceff42427ad980a41e619 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1ef251aa63972fe6c0f107f5abd139b7d0f7987a | kernel.org | Patch |
| https://git.kernel.org/stable/c/6045ea5ca6e3fa13f8a9fafb1c535c86e124c14d | kernel.org | Patch |
| https://git.kernel.org/stable/c/e367599529dc42578545a7f85fde517b35b3cda7 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.11, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | kernel.org |