7.8

CVE-2026-64583

usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown

The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() returns.  devm releases resources in reverse
LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() ->
bdc_mem_free() manually before returning: bdc_udc_exit() tears down
individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() ->
bdc_mem_free() frees and NULLs the DMA-coherent status-report ring
(bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array.  Both happen while
the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)
remains deliverable in the window up to the post-remove devm
free_irq().

On receipt of a shared interrupt in that window, bdc_udc_interrupt()
dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA)
and dispatches sr_handler callbacks that index into bdc_ep_array,
causing a NULL-deref or use-after-free.

The same window affects the delayed_work bdc->func_wake_notify, which is
armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change()
-> schedule_delayed_work() and may self-rearm from its own callback
bdc_func_wake_timer().  No cancel exists anywhere in the driver, so a
queued work item that fires after bdc_remove() returns and the bdc
structure is devm-freed dereferences freed memory.

Replace devm_request_irq() with request_irq() and add an explicit
free_irq(bdc->irq, bdc) in bdc_remove().  Clear BDC_GIE before
free_irq() to stop the device from asserting interrupts, then
free_irq() drains any in-flight handler, then cancel_delayed_work_sync()
drains the func_wake_notify delayed work.  This ordering ensures the
IRQ handler and delayed work cannot interfere with the subsequent
endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit().  Wire the
matching free_irq() into the bdc_udc_init() error path so the IRQ is
released on probe failure, and route the bdc_init_ep() failure through
err0 instead of returning directly.

This issue was found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < 0b0b76e31b3991a899ae724eb97d359de0c0f1b1
Status affected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < 3fe181952b8a1aeb167d4503c794c0f5050f08ed
Status affected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < 1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8
Status affected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < f6fc21ec7ccd83726ba766d73d0b8cc03e726475
Status affected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < dcf3e2f164435b5844706cb8eefef29ebee0eedb
Status affected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < d4964a74717107697999f48bcb4e80a9c0679a27
Status affected
Version efed421a94e62a7ddbc76acba4312b70e4be958f
Version < 0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.19
Status affected
Version 0
Version < 3.19
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8
https://git.kernel.org/stable/c/f6fc21ec7ccd83726ba766d73d0b8cc03e726475
https://git.kernel.org/stable/c/dcf3e2f164435b5844706cb8eefef29ebee0eedb
https://git.kernel.org/stable/c/d4964a74717107697999f48bcb4e80a9c0679a27
https://git.kernel.org/stable/c/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb
https://git.kernel.org/stable/c/0b0b76e31b3991a899ae724eb97d359de0c0f1b1
https://git.kernel.org/stable/c/3fe181952b8a1aeb167d4503c794c0f5050f08ed