Answer in brief
CVE-2026-64345 records a Unknown severity vulnerability in usb: gadget: f_printer: take kref only for successful open. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <94ec20d97aa51547965a539f660a1fe79c6929a3 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <75c0ad13e136961328253742501b4efc3988a587 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <bf20c94fa6aaff945f0ae3a23f3212cd299f28d9 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <8a5eba992c862b0c94411eecf9b7121e8636db38 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <7f1f24c367938c5537e2308bf9a965f051d14774 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <30adce93d5c4a5a1ec29d9249e3fdfcc391d406b || 25c95c6bd4dc50a3c20de0fa7f450ea02b2320fc || 4a47581cf010dc351d8069978080fdb000c0776d || d9fe88b2a38dc700bf5bd3a09c7cd11bbc248367 || cedb0187b8ba929c3f76f28e6bc25804d65f8a54 || e9e791f5c39ab30e374a3b1a9c25ca7ff24988f3 || 34f026263889e2827e04acdc3a0eb9ecbd191ef0 || 5f845e5d18d151230476cf90aa46449f69ba2ef1 || >=4.4.241 <4.5 || >=4.9.241 <4.10 || >=4.14.203 <4.15 || >=4.19.154 <4.20 || >=5.4.73 <5.5 || >=5.8.17 <5.9 || >=5.9.2 <5.10 | 94ec20d97aa51547965a539f660a1fe79c6929a3, 75c0ad13e136961328253742501b4efc3988a587, bf20c94fa6aaff945f0ae3a23f3212cd299f28d9, 8a5eba992c862b0c94411eecf9b7121e8636db38, 7f1f24c367938c5537e2308bf9a965f051d14774, 30adce93d5c4a5a1ec29d9249e3fdfcc391d406b, 4.5, 4.10, 4.15, 4.20, 5.5, 5.9, 5.10 |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 11, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the return value. VFS does not call ->release() for a failed open, so every rejected second open permanently leaks one reference. Move kref_get() into the successful-open branch.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-64345 records a Unknown severity vulnerability in usb: gadget: f_printer: take kref only for successful open. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <94ec20d97aa51547965a539f660a1fe79c6929a3 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <75c0ad13e136961328253742501b4efc3988a587 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <bf20c94fa6aaff945f0ae3a23f3212cd299f28d9 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <8a5eba992c862b0c94411eecf9b7121e8636db38 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <7f1f24c367938c5537e2308bf9a965f051d14774 || >=e8d5f92b8d30bb4ade76494490c3c065e12411b1 <30adce93d5c4a5a1ec29d9249e3fdfcc391d406b || 25c95c6bd4dc50a3c20de0fa7f450ea02b2320fc || 4a47581cf010dc351d8069978080fdb000c0776d || d9fe88b2a38dc700bf5bd3a09c7cd11bbc248367 || cedb0187b8ba929c3f76f28e6bc25804d65f8a54 || e9e791f5c39ab30e374a3b1a9c25ca7ff24988f3 || 34f026263889e2827e04acdc3a0eb9ecbd191ef0 || 5f845e5d18d151230476cf90aa46449f69ba2ef1 || >=4.4.241 <4.5 || >=4.9.241 <4.10 || >=4.14.203 <4.15 || >=4.19.154 <4.20 || >=5.4.73 <5.5 || >=5.8.17 <5.9 || >=5.9.2 <5.10 | 94ec20d97aa51547965a539f660a1fe79c6929a3, 75c0ad13e136961328253742501b4efc3988a587, bf20c94fa6aaff945f0ae3a23f3212cd299f28d9, 8a5eba992c862b0c94411eecf9b7121e8636db38, 7f1f24c367938c5537e2308bf9a965f051d14774, 30adce93d5c4a5a1ec29d9249e3fdfcc391d406b, 4.5, 4.10, 4.15, 4.20, 5.5, 5.9, 5.10 |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 11, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_printer: take kref only for successful open printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the return value. VFS does not call ->release() for a failed open, so every rejected second open permanently leaks one reference. Move kref_get() into the successful-open branch.
Quoted source text, attributed separately from HOL analysis.