CVE-2026-90023EPSS p11.2%
CVE-2026-90023CVE-2026-90023
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
Previously fsg_num_buffers_validate() was removed as it was not
necessary due to Kconfig setting the limits for n from 2 to 256 with
default as 2. However, setting the page content in such a way that
kstrtou8() reflects n value as either 0 or 1 bypasses these
restrictions leading to a null pointer dereference if n is 0. Fix
this by adding a check for n < 2 and returning -EINVAL if n is
either 0 or 1 consistent with Kconfig logic.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-03 |