Answer in brief
CVE-2026-93214 records a Unknown severity vulnerability in usb: gadget: f_tcm: fix deadlock in usbg_make_tpg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4bb8548df632187d5db50878e71804af5f7c51ad <abad5daa41cf5d0a0a9cba0397d3a0e7f11e0277 || >=4bb8548df632187d5db50878e71804af5f7c51ad <3639438a4c83ffc2e564c8c010b92137c5d11cfa || >=4bb8548df632187d5db50878e71804af5f7c51ad <78a14ea2284825055ab6c2a1f3489510f560f3a2 || >=4bb8548df632187d5db50878e71804af5f7c51ad <eef3e62f90d86c1c5651742f84ecc9db1814a893 || >=4bb8548df632187d5db50878e71804af5f7c51ad <f81a2da137b029a282b9bc64d2f267d242948659 || >=4bb8548df632187d5db50878e71804af5f7c51ad <6bcd9ee6ad6989d1d85a7459687e45b7ad7568d9 || >=4bb8548df632187d5db50878e71804af5f7c51ad <d90b0f90e30cd59b36005a4016b15cf02bcd7fb2 || >=4bb8548df632187d5db50878e71804af5f7c51ad <9dbf74f4022f80f7669d2b3c22c5deb46c1b5674 | abad5daa41cf5d0a0a9cba0397d3a0e7f11e0277, 3639438a4c83ffc2e564c8c010b92137c5d11cfa, 78a14ea2284825055ab6c2a1f3489510f560f3a2, eef3e62f90d86c1c5651742f84ecc9db1814a893, f81a2da137b029a282b9bc64d2f267d242948659, 6bcd9ee6ad6989d1d85a7459687e45b7ad7568d9, d90b0f90e30cd59b36005a4016b15cf02bcd7fb2, 9dbf74f4022f80f7669d2b3c22c5deb46c1b5674 |
| Linux/Linuxgeneric | 4.5 | Not reported |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() usbg_make_tpg() held dep_lock while calling configfs_depend_item_unlocked(), which acquires the configfs root inode lock when operating across subsystems. This creates a circular lock dependency with configfs_rmdir(): dep_lock -> configfs root inode lock -> su_mutex -> dep_lock In usbg_make_tpg(), dep_lock only serialized the read of opts->ready, which is a monotonic flag that transitions from false to true exactly once (in tcm_set_name()) and never reverts. Remove dep_lock from usbg_make_tpg() entirely and use READ_ONCE/WRITE_ONCE to access opts->ready locklessly instead.
Quoted source text, attributed separately from HOL analysis.