{"id":"CVE-2026-93214","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: fix deadlock in usbg_make_tpg()\n\nusbg_make_tpg() held dep_lock while calling\nconfigfs_depend_item_unlocked(), which acquires the configfs root\ninode…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: fix deadlock in usbg_make_tpg()\n\nusbg_make_tpg() held dep_lock while calling\nconfigfs_depend_item_unlocked(), which acquires the configfs root\ninode…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < abad5daa41cf5d0a0a9cba0397d3a0e7f11e0277","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < 3639438a4c83ffc2e564c8c010b92137c5d11cfa","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < 78a14ea2284825055ab6c2a1f3489510f560f3a2","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < eef3e62f90d86c1c5651742f84ecc9db1814a893","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < f81a2da137b029a282b9bc64d2f267d242948659","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < 6bcd9ee6ad6989d1d85a7459687e45b7ad7568d9","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < d90b0f90e30cd59b36005a4016b15cf02bcd7fb2","Linux >= 4bb8548df632187d5db50878e71804af5f7c51ad < 9dbf74f4022f80f7669d2b3c22c5deb46c1b5674","Linux 4.5"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T16:17:16.397","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93214","references":[{"url":"https://git.kernel.org/stable/c/3639438a4c83ffc2e564c8c010b92137c5d11cfa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bcd9ee6ad6989d1d85a7459687e45b7ad7568d9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78a14ea2284825055ab6c2a1f3489510f560f3a2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9dbf74f4022f80f7669d2b3c22c5deb46c1b5674","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abad5daa41cf5d0a0a9cba0397d3a0e7f11e0277","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d90b0f90e30cd59b36005a4016b15cf02bcd7fb2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eef3e62f90d86c1c5651742f84ecc9db1814a893","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f81a2da137b029a282b9bc64d2f267d242948659","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T15:45:56.670Z","slug":"CVE-2026-93214","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: fix deadlock in usbg_make_tpg()\n\nusbg_make_tpg() held dep_lock while calling\nconfigfs_depend_item_unlocked(), which acquires the configfs root\ninode lock when operating across subsystems. This creates a circular\nlock dependency with configfs_rmdir():\n\n  dep_lock -> configfs root inode lock -> su_mutex -> dep_lock\n\nIn usbg_make_tpg(), dep_lock only serialized the read of opts->ready,\nwhich is a monotonic flag that transitions from false to true exactly\nonce (in tcm_set_name()) and never reverts. Remove dep_lock from\nusbg_make_tpg() entirely and use READ_ONCE/WRITE_ONCE to access\nopts->ready locklessly instead.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}