CVE-2026-80830

medium

Description

In the Linux kernel, the following vulnerability has been resolved: usb: core: Add lock to usb_wakeup_notification() Add a spin lock to usb_wakeup notification to prevent a race condition with dereferencing freed memory. This could be hit by the xHCI driver as it calls this function from an IRQ and could race with the hub_disconnect() function, which properly grabs this lock to protect the state of the device.

References

https://git.kernel.org/stable/c/e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6

https://git.kernel.org/stable/c/d80b946804674069db7ce6657319a71cf8eeaa5a

https://git.kernel.org/stable/c/bf2288583b4e072bdff17a233963619e4bc7a8b5

https://git.kernel.org/stable/c/a7a16167991c88016acef720927400404039d850

https://git.kernel.org/stable/c/975ef630393c07fcbebf94f4d97043161b77a6ce

https://git.kernel.org/stable/c/960ca456faf61824b178f47967340300b24183db

https://git.kernel.org/stable/c/7c48aa0c1e79116b8af4b988d16ee29b427d6491

https://git.kernel.org/stable/c/71cfda2fdf78041a01e9d94143baa79feabbdbf6

https://git.kernel.org/stable/c/04ab260407972e631c86f2bc576cd8e64d65b325

Details

Source: Mitre, NVD

Published: 2026-09-04

Updated: 2026-09-04

Risk Information

CVSS v2

Base Score: 5.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: Medium

EPSS

EPSS: 0.00195