-

CVE-2026-80563

gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind

In the Linux kernel, the following vulnerability has been resolved:

gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind

The "trigger" debugfs file has a hand-rolled ->write handler
(trigger_write()) that dereferences the per-device gpio_la_poll_priv. The
file is created with debugfs_create_file_unsafe(), and the handler never
takes a debugfs reference. Nothing keeps the object alive while the
handler runs.

priv is allocated with devm_kzalloc(). devres frees it when the platform
device is unbound. debugfs_create_file_unsafe() installs no full_proxy
wrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not
wait for an in-flight trigger_write(). The blob_lock taken there does not
help, because trigger_write() never takes it. A write that races an unbind
therefore writes into freed memory:

  trigger_write()                  gpio_la_poll_remove()
    priv = m->private
    buf = memdup_user()  [may sleep]
                                     mutex_lock(&priv->blob_lock)
                                     debugfs_remove_recursive()  [no wait]
                                     mutex_unlock(&priv->blob_lock)
                                   (remove returns; devres frees priv)
    priv->trig_data = buf   <-- use-after-free write
    priv->trig_len  = count

The race is reachable by root via
/sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind.

Create "trigger" with debugfs_create_file() instead. Its full_proxy
wrapper makes debugfs_remove_recursive() drain any in-flight ->write
before it returns.

The use-after-free is confirmed under KASAN with a minimal reproducer of
the same debugfs_create_file_unsafe() plus devm_kzalloc() pattern
(available on request); it produces a slab-use-after-free write in the
handler.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7828b7bbbf2074dd7dd14d87f50bc5ce9036d692
Version < 49a1ebb1ef2c8ada300c174b65273810abb4e326
Status affected
Version 7828b7bbbf2074dd7dd14d87f50bc5ce9036d692
Version < 23e9f32c0c7d2043e39655cff5ee3ddf29a43f80
Status affected
Version 7828b7bbbf2074dd7dd14d87f50bc5ce9036d692
Version < 24bef4918f6ab806260476e2f93d8f791fd17449
Status affected
Version 7828b7bbbf2074dd7dd14d87f50bc5ce9036d692
Version < 44f3468a0aef1aabdad551898ab7cfa2a9d20e99
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/49a1ebb1ef2c8ada300c174b65273810abb4e326
https://git.kernel.org/stable/c/23e9f32c0c7d2043e39655cff5ee3ddf29a43f80
https://git.kernel.org/stable/c/24bef4918f6ab806260476e2f93d8f791fd17449
https://git.kernel.org/stable/c/44f3468a0aef1aabdad551898ab7cfa2a9d20e99