Answer in brief
CVE-2026-43421 records a Medium severity (CVSS 5.5) vulnerability in usb: gadget: f_ncm: Fix net_device lifecycle with device_move. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 3.11 | Not reported |
| Linux/Linuxgeneric | >=40d133d7f542616cf9538508a372306e626a16e9 <7c97366f5dac5255e60a317ffe3a5b18f3745547 || >=40d133d7f542616cf9538508a372306e626a16e9 <36c41e9724c9a7a7cda37f5a4e9d94f25c8031c4 || >=40d133d7f542616cf9538508a372306e626a16e9 <93f116c3393a22acab96ad1bef12b2572eb80ca4 || >=40d133d7f542616cf9538508a372306e626a16e9 <e584cb58a2ea7ff4d3a4bc43d5ca512ed3ecb77d || >=40d133d7f542616cf9538508a372306e626a16e9 <85acaba2f42b557499bab3608307f17bf13beb69 || >=40d133d7f542616cf9538508a372306e626a16e9 <ec35c1969650e7cb6c8a91020e568ed46e3551b0 | 7c97366f5dac5255e60a317ffe3a5b18f3745547, 36c41e9724c9a7a7cda37f5a4e9d94f25c8031c4, 93f116c3393a22acab96ad1bef12b2572eb80ca4, e584cb58a2ea7ff4d3a4bc43d5ca512ed3ecb77d, 85acaba2f42b557499bab3608307f17bf13beb69, ec35c1969650e7cb6c8a91020e568ed46e3551b0 |
Published upstream
May 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Fix net_device lifecycle with device_move The network device outlived its parent gadget device during disconnection, resulting in dangling sysfs links and null pointer dereference problems. A prior attempt to solve this by removing SET_NETDEV_DEV entirely [1] was reverted due to power management ordering concerns and a NO-CARRIER regression. A subsequent attempt to defer net_device allocation to bind [2] broke 1:1 mapping between function instance and network device, making it impossible for configfs to report the resolved interface name. This results in a regression where the DHCP server fails on pmOS. Use device_move to reparent the net_device between the gadget device and /sys/devices/virtual/ across bind/unbind cycles. This preserves the network interface across USB reconnection, allowing the DHCP server to retain their binding. Introduce gether_attach_gadget()/gether_detach_gadget() helpers and use __free(detach_gadget) macro to undo attachment on bind failure. The bind_count ensures device_move executes only on the first bind. [1] https://lore.kernel.org/lkml/[email protected]/ [2] https://lore.kernel.org/linux-usb/[email protected]/
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-43421 records a Medium severity (CVSS 5.5) vulnerability in usb: gadget: f_ncm: Fix net_device lifecycle with device_move. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 3.11 | Not reported |
| Linux/Linuxgeneric | >=40d133d7f542616cf9538508a372306e626a16e9 <7c97366f5dac5255e60a317ffe3a5b18f3745547 || >=40d133d7f542616cf9538508a372306e626a16e9 <36c41e9724c9a7a7cda37f5a4e9d94f25c8031c4 || >=40d133d7f542616cf9538508a372306e626a16e9 <93f116c3393a22acab96ad1bef12b2572eb80ca4 || >=40d133d7f542616cf9538508a372306e626a16e9 <e584cb58a2ea7ff4d3a4bc43d5ca512ed3ecb77d || >=40d133d7f542616cf9538508a372306e626a16e9 <85acaba2f42b557499bab3608307f17bf13beb69 || >=40d133d7f542616cf9538508a372306e626a16e9 <ec35c1969650e7cb6c8a91020e568ed46e3551b0 | 7c97366f5dac5255e60a317ffe3a5b18f3745547, 36c41e9724c9a7a7cda37f5a4e9d94f25c8031c4, 93f116c3393a22acab96ad1bef12b2572eb80ca4, e584cb58a2ea7ff4d3a4bc43d5ca512ed3ecb77d, 85acaba2f42b557499bab3608307f17bf13beb69, ec35c1969650e7cb6c8a91020e568ed46e3551b0 |
Published upstream
May 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Fix net_device lifecycle with device_move The network device outlived its parent gadget device during disconnection, resulting in dangling sysfs links and null pointer dereference problems. A prior attempt to solve this by removing SET_NETDEV_DEV entirely [1] was reverted due to power management ordering concerns and a NO-CARRIER regression. A subsequent attempt to defer net_device allocation to bind [2] broke 1:1 mapping between function instance and network device, making it impossible for configfs to report the resolved interface name. This results in a regression where the DHCP server fails on pmOS. Use device_move to reparent the net_device between the gadget device and /sys/devices/virtual/ across bind/unbind cycles. This preserves the network interface across USB reconnection, allowing the DHCP server to retain their binding. Introduce gether_attach_gadget()/gether_detach_gadget() helpers and use __free(detach_gadget) macro to undo attachment on bind failure. The bind_count ensures device_move executes only on the first bind. [1] https://lore.kernel.org/lkml/[email protected]/ [2] https://lore.kernel.org/linux-usb/[email protected]/
Quoted source text, attributed separately from HOL analysis.