-

CVE-2026-63905

usbip: vudc: Fix use after free bug in vudc_remove due to race condition

In the Linux kernel, the following vulnerability has been resolved:

usbip: vudc: Fix use after free bug in vudc_remove due to race condition

This patch follows up Zheng Wang's 2023 report of a use-after-free in
vudc_remove(). The original thread stalled on Shuah Khan's request for
runtime testing of the unplug/unbind path. This patch supplies that
testing and keeps Zheng's original fix shape.

In vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer().
usbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer().
vudc_remove() can then free the containing struct vudc while the timer is
still pending or executing.

KASAN confirms the race on an unpatched x86_64 QEMU guest with
CONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop
that repeatedly writes a socket fd to usbip_sockfd, closes the socket
pair, and unbinds/rebinds usbip-vudc.0:

  BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0
  Write of size 8 at addr ffff888001b80740 by task trigger_and_unb/239
  Allocated by task 239:
    vudc_probe+0x4d/0xaa0
  Freed by task 239:
    kfree+0x18f/0x520
    device_release_driver_internal+0x388/0x540
    unbind_store+0xd9/0x100

This lands in the timer core rather than v_timer() itself because the
embedded timer_list is being walked after its containing struct vudc has
already been freed. The underlying lifetime bug is the same one Zheng
reported.

With v_stop_timer() called from vudc_remove() and the timer deleted
synchronously, the same harness completed 5000 bind/unbind iterations
with no KASAN report.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < 61704e5cf9cd7464b510eb606e7e2978b1160a64
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < dcc1c90b28b28b7c493547506297e78653f81952
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < 1036ac6148995feaf486014d32bf26bf993c06a9
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < a0638db2340ee053ab0450656a763fd111475e54
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < d07ed707467ce05ea9c03412d0c5ee9d0fe386a6
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < 88d459e5b5a46da1ef9fd6f52d9439343edeec88
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < 207bf80362df3fce8ebc9723351dcb1bc6d9ed0f
Status affected
Version b6a0ca11186759ad7045d68a5447b1e89f658384
Version < d96209626a29ea64666be98c30b30ac82e5f1be6
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version 0
Version < 4.7
Status unaffected
Version <= 5.10.*
Version 5.10.259
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.114
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/61704e5cf9cd7464b510eb606e7e2978b1160a64
https://git.kernel.org/stable/c/dcc1c90b28b28b7c493547506297e78653f81952
https://git.kernel.org/stable/c/1036ac6148995feaf486014d32bf26bf993c06a9
https://git.kernel.org/stable/c/a0638db2340ee053ab0450656a763fd111475e54
https://git.kernel.org/stable/c/d07ed707467ce05ea9c03412d0c5ee9d0fe386a6
https://git.kernel.org/stable/c/88d459e5b5a46da1ef9fd6f52d9439343edeec88
https://git.kernel.org/stable/c/207bf80362df3fce8ebc9723351dcb1bc6d9ed0f
https://git.kernel.org/stable/c/d96209626a29ea64666be98c30b30ac82e5f1be6