0.0
NA
CVE-2026-64594
usb: gadget: f_fs: initialize reset_work at allocation time
Description

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: initialize reset_work at allocation time ffs_fs_kill_sb() unconditionally calls cancel_work_sync() on ffs->reset_work when a functionfs instance is unmounted: ffs_data_reset(ffs); cancel_work_sync(&ffs->reset_work); However ffs->reset_work is only ever initialized via INIT_WORK() in ffs_func_set_alt() and ffs_func_disable(), and only on the FFS_DEACTIVATED path. That state is reached solely by ffs_data_closed() when the instance is mounted with the "no_disconnect" option, so for the common case (no "no_disconnect", or mounted and unmounted without ever being deactivated) reset_work is never initialized. ffs_data_new() allocates the ffs_data with kzalloc_obj() and does not initialize reset_work, and ffs_data_reset()/ffs_data_clear() do not touch it either, so reset_work.func is left NULL. cancel_work_sync() on such a work then trips the WARN_ON(!work->func) guard in __flush_work(): WARNING: kernel/workqueue.c:4301 at __flush_work+0x330/0x360, CPU#3: umount Call trace: __flush_work cancel_work_sync ffs_fs_kill_sb [usb_f_fs] deactivate_locked_super deactivate_super cleanup_mnt __cleanup_mnt task_work_run exit_to_user_mode_loop el0_svc On older kernels cancel_work_sync() on a zero-initialized work struct was a silent no-op, which hid the missing initialization. Initialize reset_work once in ffs_data_new() so it is always valid for the lifetime of the ffs_data, and drop the now-redundant INIT_WORK() calls from the two deactivation paths.

INFO

Published Date :

Aug. 6, 2026, 8:16 a.m.

Last Modified :

Aug. 6, 2026, 8:16 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-64594 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Initialize work structures in the Linux kernel's functionfs to prevent potential issues during unmounting.
  • Initialize reset_work in ffs_data_new().
  • Remove redundant INIT_WORK calls.
  • Apply the Linux kernel patch.
  • Update the Linux kernel.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-64594 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-64594 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-64594 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-64594 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 06, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': '7fe895e0a9651518c4fc082487da770ff9c14c7f', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': '0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': 'cb19e54ebe9baf3c3243083ade65c937339ccb7b', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': 'd5631081be07f20e764d3cb5c98ac0a1004fba51', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': 'c36393b0d14e1e9783888f821ffe29381b8f46dc', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': '69faa3779250df14f51d5084f938a99809546e52', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': 'ba1867999dbc4085e6d8c52ac5266005b8b2bf07', 'versionType': 'git'}, {'status': 'affected', 'version': '18d6b32fca3841f7cd9479b4024abd8a9b299281', 'lessThan': '3137b243c93982fe3460335e12f9247739766e10', 'versionType': 'git'}], 'programFiles': ['drivers/usb/gadget/function/f_fs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc3', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/gadget/function/f_fs.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: initialize reset_work at allocation time ffs_fs_kill_sb() unconditionally calls cancel_work_sync() on ffs->reset_work when a functionfs instance is unmounted: ffs_data_reset(ffs); cancel_work_sync(&ffs->reset_work); However ffs->reset_work is only ever initialized via INIT_WORK() in ffs_func_set_alt() and ffs_func_disable(), and only on the FFS_DEACTIVATED path. That state is reached solely by ffs_data_closed() when the instance is mounted with the "no_disconnect" option, so for the common case (no "no_disconnect", or mounted and unmounted without ever being deactivated) reset_work is never initialized. ffs_data_new() allocates the ffs_data with kzalloc_obj() and does not initialize reset_work, and ffs_data_reset()/ffs_data_clear() do not touch it either, so reset_work.func is left NULL. cancel_work_sync() on such a work then trips the WARN_ON(!work->func) guard in __flush_work(): WARNING: kernel/workqueue.c:4301 at __flush_work+0x330/0x360, CPU#3: umount Call trace: __flush_work cancel_work_sync ffs_fs_kill_sb [usb_f_fs] deactivate_locked_super deactivate_super cleanup_mnt __cleanup_mnt task_work_run exit_to_user_mode_loop el0_svc On older kernels cancel_work_sync() on a zero-initialized work struct was a silent no-op, which hid the missing initialization. Initialize reset_work once in ffs_data_new() so it is always valid for the lifetime of the ffs_data, and drop the now-redundant INIT_WORK() calls from the two deactivation paths.
    Added Reference https://git.kernel.org/stable/c/0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7
    Added Reference https://git.kernel.org/stable/c/3137b243c93982fe3460335e12f9247739766e10
    Added Reference https://git.kernel.org/stable/c/69faa3779250df14f51d5084f938a99809546e52
    Added Reference https://git.kernel.org/stable/c/7fe895e0a9651518c4fc082487da770ff9c14c7f
    Added Reference https://git.kernel.org/stable/c/ba1867999dbc4085e6d8c52ac5266005b8b2bf07
    Added Reference https://git.kernel.org/stable/c/c36393b0d14e1e9783888f821ffe29381b8f46dc
    Added Reference https://git.kernel.org/stable/c/cb19e54ebe9baf3c3243083ade65c937339ccb7b
    Added Reference https://git.kernel.org/stable/c/d5631081be07f20e764d3cb5c98ac0a1004fba51
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.