{"id":"CVE-2026-64594","summary":"usb: gadget: f_fs: initialize reset_work at allocation time","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: initialize reset_work at allocation time\n\nffs_fs_kill_sb() unconditionally calls cancel_work_sync() on\nffs-\u003ereset_work when a functionfs instance is unmounted:\n\n\tffs_data_reset(ffs);\n\tcancel_work_sync(&ffs-\u003ereset_work);\n\nHowever ffs-\u003ereset_work is only ever initialized via INIT_WORK() in\nffs_func_set_alt() and ffs_func_disable(), and only on the\nFFS_DEACTIVATED path. That state is reached solely by ffs_data_closed()\nwhen the instance is mounted with the \"no_disconnect\" option, so for the\ncommon case (no \"no_disconnect\", or mounted and unmounted without ever\nbeing deactivated) reset_work is never initialized.\n\nffs_data_new() allocates the ffs_data with kzalloc_obj() and does not\ninitialize reset_work, and ffs_data_reset()/ffs_data_clear() do not touch\nit either, so reset_work.func is left NULL. cancel_work_sync() on such a\nwork then trips the WARN_ON(!work-\u003efunc) guard in __flush_work():\n\n  WARNING: kernel/workqueue.c:4301 at __flush_work+0x330/0x360, CPU#3: umount\n  Call trace:\n   __flush_work\n   cancel_work_sync\n   ffs_fs_kill_sb [usb_f_fs]\n   deactivate_locked_super\n   deactivate_super\n   cleanup_mnt\n   __cleanup_mnt\n   task_work_run\n   exit_to_user_mode_loop\n   el0_svc\n\nOn older kernels cancel_work_sync() on a zero-initialized work struct was\na silent no-op, which hid the missing initialization.\n\nInitialize reset_work once in ffs_data_new() so it is always valid for\nthe lifetime of the ffs_data, and drop the now-redundant INIT_WORK()\ncalls from the two deactivation paths.","modified":"2026-08-08T03:48:19.088022295Z","published":"2026-08-06T07:13:50.309Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64594.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3137b243c93982fe3460335e12f9247739766e10"},{"type":"WEB","url":"https://git.kernel.org/stable/c/69faa3779250df14f51d5084f938a99809546e52"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7fe895e0a9651518c4fc082487da770ff9c14c7f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ba1867999dbc4085e6d8c52ac5266005b8b2bf07"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c36393b0d14e1e9783888f821ffe29381b8f46dc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cb19e54ebe9baf3c3243083ade65c937339ccb7b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d5631081be07f20e764d3cb5c98ac0a1004fba51"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64594.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64594"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"18d6b32fca3841f7cd9479b4024abd8a9b299281"},{"fixed":"7fe895e0a9651518c4fc082487da770ff9c14c7f"},{"fixed":"0de6ebbabfbbc9c28350283dc97d8a519d5c6dd7"},{"fixed":"cb19e54ebe9baf3c3243083ade65c937339ccb7b"},{"fixed":"d5631081be07f20e764d3cb5c98ac0a1004fba51"},{"fixed":"c36393b0d14e1e9783888f821ffe29381b8f46dc"},{"fixed":"69faa3779250df14f51d5084f938a99809546e52"},{"fixed":"ba1867999dbc4085e6d8c52ac5266005b8b2bf07"},{"fixed":"3137b243c93982fe3460335e12f9247739766e10"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64594.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64594.json"}}],"schema_version":"1.8.0"}