CVE-2026-31722
Description
A flaw was found in the Linux kernel's USB gadget RNDIS (Remote Network Driver Interface Specification) function. During the unbinding process of a USB gadget device, the associated network device (net_device) may not be correctly reparented, resulting in dangling symbolic links within the system's sysfs filesystem. This improper management of the device lifecycle could potentially lead to system instability or unexpected behavior.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (Other); DoS: Resource Consumption (Memory); DoS: Resource Consumption (CPU)
An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and prevent all other processes from accessing the same type of resource. Frequently-affected resources include memory, CPU, disk space, power or battery, etc.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.