7.8

CVE-2026-80622

char: tlclk: fix use-after-free in tlclk_cleanup()

In the Linux kernel, the following vulnerability has been resolved:

char: tlclk: fix use-after-free in tlclk_cleanup()

This patch improves the module cleanup process in the tlclk driver to
prevent potential use-after-free and race conditions.

Currently, the file_operations structure does not specify the .owner
field, which could allow the module to be unloaded while user-space
processes are still interacting with the device. Additionally, the
tlclk_cleanup() function frees the alarm_events memory before ensuring
that blocked processes in the waitqueue are fully awakened and that the
switchover_timer has completed.

To address these cases, this patch:
- Sets '.owner = THIS_MODULE' in tlclk_fops to safely defer module
  unloading while the device is in use.
- Updates tlclk_cleanup() to explicitly wake up all blocked readers
  (wake_up_all), properly release hardware I/O regions, and safely
  delete the timer (timer_delete_sync) prior to freeing memory.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < 09d8d2a46a9ec9ff728f3159a174a2ab25dd0f0a
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < 96902299a22d126ef5eb3f45cd5d8ceea9e6a735
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < 166dd1d5265e067459e674c11688919901813ec2
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < 764723bd67a6c8f53a8d8309211fb039e2ebcf49
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < c3f0cd76561ae611c2d247ee96dfd559e4197cb7
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < 3d5e4cc0d9dce79b0429da3134ac7b072ab9009f
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < 42223445607a9a5df3cb1c4729abfe3a5085e7ce
Status affected
Version 1a80ba88273097933f93b1f40537337416798c70
Version < bbf003b7794d6ad6f939fdd29f1f1bde8ac554c1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.15
Status affected
Version 0
Version < 2.6.15
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/09d8d2a46a9ec9ff728f3159a174a2ab25dd0f0a
https://git.kernel.org/stable/c/96902299a22d126ef5eb3f45cd5d8ceea9e6a735
https://git.kernel.org/stable/c/166dd1d5265e067459e674c11688919901813ec2
https://git.kernel.org/stable/c/764723bd67a6c8f53a8d8309211fb039e2ebcf49
https://git.kernel.org/stable/c/c3f0cd76561ae611c2d247ee96dfd559e4197cb7
https://git.kernel.org/stable/c/3d5e4cc0d9dce79b0429da3134ac7b072ab9009f
https://git.kernel.org/stable/c/42223445607a9a5df3cb1c4729abfe3a5085e7ce
https://git.kernel.org/stable/c/bbf003b7794d6ad6f939fdd29f1f1bde8ac554c1