Answer in brief
CVE-2026-93056 records a Unknown severity vulnerability in usb: gadget: f_uac1_legacy: remove broken string configfs attributes. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <745adfe6c337f3d5d7737d57529d14a208151b45 || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <6351ba62778f72dc4f6bc18bfa99e618829cff0d || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <021b58ac3e58cffa68ed9585ff492a19e98414f6 || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <fd43eae7d539ea7cfc7c9f0d3f0eaa890415e8a7 || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <8b9335aec93975bb9186d63993a5a610e5066ffc || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <2ed25c9d4400cf90d9201657963a231c27a5ea57 || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <977659adb341f6e30fb00dcf183f63f29df879e2 || >=0854611a19ae4dfa56569e6f640017a1d2dd3312 <590d74ec8f488e06b9f1c0f8f0941f45531f3a55 | 745adfe6c337f3d5d7737d57529d14a208151b45, 6351ba62778f72dc4f6bc18bfa99e618829cff0d, 021b58ac3e58cffa68ed9585ff492a19e98414f6, fd43eae7d539ea7cfc7c9f0d3f0eaa890415e8a7, 8b9335aec93975bb9186d63993a5a610e5066ffc, 2ed25c9d4400cf90d9201657963a231c27a5ea57, 977659adb341f6e30fb00dcf183f63f29df879e2, 590d74ec8f488e06b9f1c0f8f0941f45531f3a55 |
| Linux/Linuxgeneric | 3.18 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: remove broken string configfs attributes The UAC1_STR_ATTRIBUTE macro defines configfs show/store handlers for the fn_play, fn_cap, and fn_cntl string options. The store function contains an inverted null check on the kstrndup() return value. This means every write attempt returns -ENOMEM on success and dereferences a NULL pointer on allocation failure. The attributes have been broken and unused for many years. Remove the UAC1_STR_ATTRIBUTE macro and the three attributes it generated. The internal defaults (FILE_PCM_PLAYBACK, FILE_PCM_CAPTURE, FILE_CONTROL) set in f_audio_alloc_inst() are unaffected.
Quoted source text, attributed separately from HOL analysis.