{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_fs: initialize reset_work at allocation time  ffs_fs_kill_sb() unconditionally calls cancel_work_sync() on ffs-\u003ereset_work when a functionfs instance is unmounted:  \tffs_data_reset(ffs); \tcancel_work_sync(\u0026ffs-\u003ereset_work);  However ffs-\u003ereset_work is only ever initialized via INIT_WORK() in ffs_func_set_alt() and ffs_func_disable(), and only on the FFS_DEACTIVATED path. That state is reached solely by ffs_data_closed() when the instance is mounted with the \"no_disconnect\" option, so for the common case (no \"no_disconnect\", or mounted and unmounted without ever being deactivated) reset_work is never initialized.  ffs_data_new() allocates the ffs_data with kzalloc_obj() and does not initialize reset_work, and ffs_data_reset()/ffs_data_clear() do not touch it either, so reset_work.func is left NULL. cancel_work_sync() on such a work then trips the WARN_ON(!work-\u003efunc) guard in __flush_work():    WARNING: kernel/workqueue.c:4301 at __flush_work+0x330/0x360, CPU#3: umount   Call trace:    __flush_work    cancel_work_sync    ffs_fs_kill_sb [usb_f_fs]    deactivate_locked_super    deactivate_super    cleanup_mnt    __cleanup_mnt    task_work_run    exit_to_user_mode_loop    el0_svc  On older kernels cancel_work_sync() on a zero-initialized work struct was a silent no-op, which hid the missing initialization.  Initialize reset_work once in ffs_data_new() so it is always valid for the lifetime of the ffs_data, and drop the now-redundant INIT_WORK() calls from the two deactivation paths.",
  "id": "DEBIAN-CVE-2026-64594",
  "modified": "2026-09-14T16:47:44.632780761Z",
  "published": "2026-08-06T08:16:34.933Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64594"
    }
  ],
  "upstream": [
    "CVE-2026-64594"
  ]
}