Commit 7fafcfdf6377 ("USB: gadget: f_midi: fixing a possible double-free in f_midi") fixes CVE-2018-20961. Commit f0f1b8cac4d8 ("usb: gadget: f_midi: fail if set_alt fails to allocate requests") avoids a context conflict when applying 7fafcfdf6377, and fixes another minor problem. Commit 7fafcfdf6377 is present in v4.9.y and v4.14.y. Thanks, Guenter