CVE-2026-31723 Details
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_subset: Fix net_device lifecycle with device_move The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks: console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -> /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering. To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.
A vulnerability exists in the Linux kernel's USB gadget function handling, specifically within the 'f_subset' driver. The issue arises during the lifecycle management of network devices (net_device) associated with USB functions. When a USB function is unbound, its parent device is destroyed, but the net_device remains, leading to dangling symlinks in the sysfs. This mismanagement can cause issues with device recognition and sysfs topology. The vulnerability affects the Linux kernel stable tree.
The vulnerability has been addressed by modifying the 'f_subset' driver to use the 'device_move()' function. This change reparents the net_device between the gadget device tree and the virtual device tree during the bind and unbind cycles, ensuring proper sysfs topology and power management. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/06524cd1c9011bee141a87e43ab878641ed3652b | kernel.org | Patch |
| https://git.kernel.org/stable/c/70707ce668494c4d35fe070dfbc7cc541b293107 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9cbc4f109bb216623894d8819fb930210ed34b21 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fde29916e4cc736c4ca6c78f331e12b2c73ccafd | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.11, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | kernel.org |