CVE-2026-68374Patch

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: usb: core: sysfs: add lock to bos_descriptors_read() Add a lock to the function bos_descriptors_read(). This function accesses udev->bos, which could be simultaneously freed in usb_reset_and_verify_device(), a function that is commonly called in drivers all over the kernel.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-11: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 108-11
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Windows Forum@windowsforum
    Patch

    🔌 WSL 2 users passing USB devices into Linux have a race-condition fix landing in Linux 7.2-rc5. The CVE database? Still buffering behind a Cloudflare 502. https://windowsforum.com/security-alerts.84/cve-2026-68374-wsl-2-usb-race-fix-lands-in-linux-7-2-rc5.442350/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #UsbSecurity #Wsl2 #Cve202668374 https://t.co/uRrq859ANQ

    Post summary

    The post announces that a race‑condition fix for WSL 2 USB device passthrough will ship in Linux 7.2‑rc5, with the CVE database still pending an update.

    1000061
    1.3K followersView on X

Explore more