{"id":"CVE-2026-97482","published":"2026-09-24T17:17:25.707","lastModified":"2026-09-28T06:16:34.200","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log\n\ngoku_irq() handles a number of bus events under a single ep0 path.\nIt already guards the gadget driver suspend/resume callbacks against a\nNULL ->driver:\n\n\tif (dev->gadget.speed != USB_SPEED_UNKNOWN\n\t\t\t&& dev->driver\n\t\t\t&& dev->driver->resume) {\n\t\tspin_unlock(&dev->lock);\n\t\tdev->driver->resume(&dev->gadget);\n\t\t...\n\t}\n\nbut the very next branch unconditionally dereferences dev->driver\nwhen an INT_USBRESET arrives:\n\n\tif (stat & INT_USBRESET) {\n\t\tACK(INT_USBRESET);\n\t\tINFO(dev, \"USB reset done, gadget %s\\n\",\n\t\t\tdev->driver->driver.name);\n\t}\n\nIf the controller raises INT_USBRESET before any gadget driver has\nbeen bound (or after one has been unbound), dev->driver is NULL and\nthe printk dereferences NULL.\n\nsmatch flags the inconsistency:\n\n  drivers/usb/gadget/udc/goku_udc.c:1618 goku_irq() error:\n  we previously assumed 'dev->driver' could be null (see line 1607)\n\nFall back to a placeholder when the gadget driver is not bound.\n\nNo functional change while a gadget driver is bound.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/10d7fc3008d5b7ec03af8e08927f1d090014c2af","tags":[]},{"url":"https://git.kernel.org/stable/c/28d78783a871cdb7a637dcb72452ff7d303430ae","tags":[]},{"url":"https://git.kernel.org/stable/c/5bf5e3fba9bc7dfd69701521dbe9809f8ccbdb02","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}