CVE-2024-38628
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix race condition use of controls after free dur
CVSS
7.8
Alto
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Publicado: 21 jun 2024 · Última mod.: 4 ago 2026 · CWE-362
0.2%EPSS · 30 días0.2%
2026-07-062026-08-03
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind. Hang on to the control IDs instead of pointers since those are correctly handled with locks.
- git.kernel.orghttps://git.kernel.org/stable/c/1b739388aa3f8dfb63a9fca777e6dfa6912d0464
- git.kernel.orghttps://git.kernel.org/stable/c/453d3fa9266e53f85377b911c19b9a4563fa88c0
- git.kernel.orghttps://git.kernel.org/stable/c/89e66809684485590ea0b32c3178e42cba36ac09
- git.kernel.orghttps://git.kernel.org/stable/c/bea73b58ab67fe581037ad9cdb93c2557590c068
- git.kernel.orghttps://git.kernel.org/stable/c/1b739388aa3f8dfb63a9fca777e6dfa6912d0464
- git.kernel.orghttps://git.kernel.org/stable/c/453d3fa9266e53f85377b911c19b9a4563fa88c0
- git.kernel.orghttps://git.kernel.org/stable/c/89e66809684485590ea0b32c3178e42cba36ac09
- git.kernel.orghttps://git.kernel.org/stable/c/bea73b58ab67fe581037ad9cdb93c2557590c068
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-15630——
——0A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be able to interact with the adoption workflow before a legitimate
device completes registration, resulting in provisioning information being
delivered to an attacker.
Successful
exploitation may allow disclosure of provisioning information intended for a
legitimate device.23hCVE-2026-441025.3 MED11.2%
——3An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.5dCVE-2026-16727—0.4%
——0Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement.
Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.5dCVE-2026-179996.5 MED3.4%
——1Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)1dCVE-2026-179937.0 ALT0.2%
——0Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)5dCVE-2026-179797.5 ALT10.5%
——3Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)5d