{"id":"DEBIAN-CVE-2021-46986","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: dwc3: gadget: Free gadget structure only after freeing endpoints  As part of commit e81a7018d93a (\"usb: dwc3: allocate gadget structure dynamically\") the dwc3_gadget_release() was added which will free the dwc-\u003egadget structure upon the device's removal when usb_del_gadget_udc() is called in dwc3_gadget_exit().  However, simply freeing the gadget results a dangling pointer situation: the endpoints created in dwc3_gadget_init_endpoints() have their dep-\u003eendpoint.ep_list members chained off the list_head anchored at dwc-\u003egadget-\u003eep_list.  Thus when dwc-\u003egadget is freed, the first dwc3_ep in the list now has a dangling prev pointer and likewise for the next pointer of the dwc3_ep at the tail of the list. The dwc3_gadget_free_endpoints() that follows will result in a use-after-free when it calls list_del().  This was caught by enabling KASAN and performing a driver unbind. The recent commit 568262bf5492 (\"usb: dwc3: core: Add shutdown callback for dwc3\") also exposes this as a panic during shutdown.  There are a few possibilities to fix this.  One could be to perform a list_del() of the gadget-\u003eep_list itself which removes it from the rest of the dwc3_ep chain.  Another approach is what this patch does, by splitting up the usb_del_gadget_udc() call into its separate \"del\" and \"put\" components.  This allows dwc3_gadget_free_endpoints() to be called before the gadget is finally freed with usb_put_gadget().","modified":"2026-09-01T20:04:36.096718773Z","published":"2024-02-28T09:15:37.540Z","upstream":["CVE-2021-46986"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-46986"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46986.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46986.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46986.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}