---
id: CVE-2026-89735
title: >-
  kernel: usb: gadget: midi2: remove default configfs groups on teardown
  (CVE-2026-89735)
summary: >-
  A flaw was found in the Linux kernel's USB gadget MIDI2 driver. The driver
  fails to properly remove default configuration file system (configfs) groups
  during teardown, leading to a resource leak. A local attacker could exploit
  this vulner…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-911
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:28:05+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89735.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89735.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89735'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532401'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89735'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89735'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89735.mbox
  - url: 'https://git.kernel.org/stable/c/0f6bffb5008f0cba9cad5ded2caccc64466a6e54'
  - url: 'https://git.kernel.org/stable/c/4beda67ee72e0c8df5b49951dd8b96f6adb25e02'
  - url: 'https://git.kernel.org/stable/c/9ea5dfb2bfef4f8a7e704d1921d8a790cb7fb700'
  - url: 'https://git.kernel.org/stable/c/a15c2acd3083461f91725760e59dff88b33c28f6'
  - url: 'https://git.kernel.org/stable/c/79dbedf40ad930f83839e564394dc5d1a54938c6'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00209
epssPercentile: 0.09821
ingestedAt: '2026-09-14T15:23:07.449Z'
---

## Overview

A flaw was found in the Linux kernel's USB gadget MIDI2 driver. The driver fails to properly remove default configuration file system (configfs) groups during teardown, leading to a resource leak. A local attacker could exploit this vulnerability to cause memory exhaustion, potentially resulting in a denial of service (DoS) on the affected system.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89735.json)

**kernel: usb: gadget: midi2: remove default configfs groups on teardown** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
