---
id: CVE-2026-89733
title: >-
  kernel: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and
  uvc_function_unbind() (CVE-2026-89733)
summary: >-
  A flaw was found in the Linux kernel's USB Video Class (UVC) gadget driver.
  This vulnerability occurs in the `uvc_function_bind()` and
  `uvc_function_unbind()` functions, where pointers to freed memory are not
  properly cleared. This can lea…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-825
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    ddb1b0d5d858584ed0d3a5aaa042ee693998c7e2
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    85dd5e8bd6776d02854f2847d83429f1f712e99c
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    502a7f5b79b7ba751988789e982924f8f496129f
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    bec7708eb3b5295d12e931db24381b7c94c72953
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    8e88ed8a374de67270d38689f2a81018909cafbb
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    9897b7da8c0ad8356c1b8649379fcb5a689462cb
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    38f822ddce9355893d734279a26ddec45182197e
  - >-
    Linux >= 0f9df939385527049c8062a099fbfa1479fe7ce0 <
    bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc
  - Linux 1efa8a5aac93d9e67075995d7d4902b57ce184f7
  - Linux e7a4b0efe62e56a0acc81d16091c6efc2a282be8
  - Linux 065f5561a20659cf17aae5f72b32b5c2695c8e00
  - Linux >= 3.2.36 < 3.3
  - Linux >= 3.4.25 < 3.5
  - Linux >= 3.7.2 < 3.8
  - Linux 3.8
published: '2026-09-11'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:28:00+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89733.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89733.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89733'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532203'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89733'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89733'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89733.mbox
  - url: 'https://git.kernel.org/stable/c/ddb1b0d5d858584ed0d3a5aaa042ee693998c7e2'
  - url: 'https://git.kernel.org/stable/c/85dd5e8bd6776d02854f2847d83429f1f712e99c'
  - url: 'https://git.kernel.org/stable/c/502a7f5b79b7ba751988789e982924f8f496129f'
  - url: 'https://git.kernel.org/stable/c/bec7708eb3b5295d12e931db24381b7c94c72953'
  - url: 'https://git.kernel.org/stable/c/8e88ed8a374de67270d38689f2a81018909cafbb'
  - url: 'https://git.kernel.org/stable/c/9897b7da8c0ad8356c1b8649379fcb5a689462cb'
  - url: 'https://git.kernel.org/stable/c/38f822ddce9355893d734279a26ddec45182197e'
  - url: 'https://git.kernel.org/stable/c/bdab5605259ba5d6ff927c1a85cc83eb3ecfdacc'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00176
epssPercentile: 0.06295
scores:
  vendor: 5.5
  cna: 7.8
ingestedAt: '2026-09-14T15:23:07.449Z'
---

## Overview

A flaw was found in the Linux kernel's USB Video Class (UVC) gadget driver. This vulnerability occurs in the `uvc_function_bind()` and `uvc_function_unbind()` functions, where pointers to freed memory are not properly cleared. This can lead to a use-after-free (UAF) condition, potentially allowing an attacker to corrupt memory, which may result in a denial of service or arbitrary code execution.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89733.json)

**kernel: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
