CVE-2026-93141EPSS p11.4%
CVE-2026-93141CVE-2026-93141
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: r8a66597: avoid double free of ep0_req in probe error path
If usb_add_gadget_udc() fails, r8a66597_probe() jumps to err_add_udc
and frees ep0_req, then falls through to clean_up2 where ep0_req is
freed again when it is non-NULL.
Remove the redundant free from err_add_udc and keep the cleanup in
clean_up2 so the request is released exactly once.
Issue found using a prototype static analysis tool
and confirmed by code review.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |