# CVE-2026-89735

## Summary

- **CVE ID:** CVE-2026-89735
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: midi2: remove default configfs groups on teardown

f_midi2_alloc_inst() creates default configfs child groups for the
default endpoint and default block using configfs_add_default_group(),
setting their internal refcount to 1.

However, during function teardown in f_midi2_free_inst() or EP cleanup
in f_midi2_ep_opts_release(), configfs_remove_default_groups() is
never called, therefore never dropping the refcount and leaking struct
f_midi2_ep_opts and f_midi2_block_opts.

Add the missing configfs_remove_default_groups() in the afformentioned
functions to free the structs properly.

## Affected Products

- Linux — Linux (8b645922b22303cec4628dbbbf6c8553d1cdec87)
- Linux — Linux (6.6)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/4beda67ee72e0c8df5b49951dd8b96f6adb25e02)
- [CNA](https://git.kernel.org/stable/c/a15c2acd3083461f91725760e59dff88b33c28f6)
- [CNA](https://git.kernel.org/stable/c/9ea5dfb2bfef4f8a7e704d1921d8a790cb7fb700)
- [CNA](https://git.kernel.org/stable/c/0f6bffb5008f0cba9cad5ded2caccc64466a6e54)
- [CNA](https://git.kernel.org/stable/c/79dbedf40ad930f83839e564394dc5d1a54938c6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._