7.8

CVE-2026-72482

gpib: fix double decrement of descriptor_busy in command_ioctl()

In the Linux kernel, the following vulnerability has been resolved:

gpib: fix double decrement of descriptor_busy in command_ioctl()

commit d1857f8296dc ("gpib: fix use-after-free in IO ioctl handlers")
introduced a descriptor_busy reference counter to pin struct
gpib_descriptor across IO ioctl operations.  In command_ioctl(), the
error path inside the loop decrements descriptor_busy and breaks, but
execution then falls through to the unconditional decrement after the
loop, underflowing the counter to -1.

This re-enables the use-after-free that the original fix was meant to
prevent: a concurrent close_dev_ioctl() sees descriptor_busy == 0 on
an actively-used descriptor and frees it.

Remove the early decrement from the error path.  The post-loop
decrement already handles all exit paths, matching the correct pattern
used in read_ioctl() and write_ioctl().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version cae26eff1b56d78bed7873cf3e60a2b1bdd4da6c
Version < fdee9f207a48ce204ec6cfceaa1459d2473600a5
Status affected
Version d1857f8296dceb75d00ab857fc3c61bc00c7f5c6
Version < 8b5f1d295dda8677e4545ce340053fcfa8b634c7
Status affected
Version d1857f8296dceb75d00ab857fc3c61bc00c7f5c6
Version < c4faab452b3c1ada003d49c477609dd80523b9bf
Status affected
Version 28c75dd143ead62e0dfac564c79d251e21d5d74b
Status affected
Version 6.18.22
Version < 6.18.40
Status affected
Version 6.19.12
Version < 6.20
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.0
Status affected
Version 0
Version < 7.0
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.038
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fdee9f207a48ce204ec6cfceaa1459d2473600a5
https://git.kernel.org/stable/c/8b5f1d295dda8677e4545ce340053fcfa8b634c7
https://git.kernel.org/stable/c/c4faab452b3c1ada003d49c477609dd80523b9bf