CVE-2026-43421: usb: gadget: f_ncm: Fix net_device lifecycle with device_move

Published May 8, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: fncm: Fix netdevice lifecycle with devicemove

The network device outlived its parent gadget device during disconnection, resulting in dangling sysfs links and null pointer dereference problems.

A prior attempt to solve this by removing SETNETDEVDEV entirely [1] was reverted due to power management ordering concerns and a NO-CARRIER regression.

A subsequent attempt to defer netdevice allocation to bind [2] broke 1:1 mapping between function instance and network device, making it impossible for configfs to report the resolved interface name. This results in a regression where the DHCP server fails on pmOS.

Use devicemove to reparent the netdevice between the gadget device and /sys/devices/virtual/ across bind/unbind cycles. This preserves the network interface across USB reconnection, allowing the DHCP server to retain their binding.

Introduce getherattachgadget()/getherdetachgadget() helpers and use free(detachgadget) macro to undo attachment on bind failure. The bindcount ensures devicemove executes only on the first bind.

[1] https://lore.kernel.org/lkml/f2a4f9847617a0929d62025748384092e5f35cce.camel@crapouillou.net/ [2] https://lore.kernel.org/linux-usb/795ea759-7eaf-4f78-81f4-01ffbf2d7961@ixit.cz/

Affected Software

7 affected components
Linux Linux kernel (usb: gadget: f_ncm)
Linux Linux kernel>=3.11<6.12.78
Linux Linux kernel>=6.13<6.18.19
Linux Linux kernel>=6.19<6.19.9
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade usb: gadget: f_ncm to a version that resolves this vulnerability.

    Patch usb: gadget: f_ncm: Fix net_device lifecycle with device_move

Event History

May 8, 2026
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which systems are most likely to be affected?

Exposure is limited to Linux systems using the USB gadget Network Control Model (f_ncm) function. The failure occurs during gadget disconnection and involves the lifecycle of the associated network device.

2

What level of access is required and what is the likely impact?

An attacker needs local access and low privileges; the CVSS vector does not require user interaction. The availability impact is rated high, while confidentiality and integrity impacts are rated none.

3

What behavior does the fix change?

The resolved change reparents the network device during bind and unbind cycles, preventing it from outliving its parent gadget device. It also preserves the network interface across USB reconnection so DHCP services can retain their binding.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203