-

CVE-2026-89737

usb: typec: thunderbolt: Disable work before freeing tbt on remove

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: thunderbolt: Disable work before freeing tbt on remove

tbt_altmode_remove() drops the plug and cable references without
draining tbt->work. The work function dereferences those references,
and can also requeue itself in its error path. The VDM callbacks can
queue the same work item.

Disable and drain tbt->work before dropping the references. This waits
for an existing invocation and prevents subsequent schedule_work()
calls from queueing it during teardown.

This issue was found by an in-house static analysis tool and confirmed
by manual code review.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 100e257386595b3f1865ca8a991e2ba74f9701ff
Version < ebb840d982a612261cfc8a7687735a140c6c7024
Status affected
Version 100e257386595b3f1865ca8a991e2ba74f9701ff
Version < 0a25484fe22f621e151367a59a82330a22ac80bc
Status affected
Version 100e257386595b3f1865ca8a991e2ba74f9701ff
Version < 92090f6ff2acc81e9dd99881dcfb4f8c1bdaabd3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ebb840d982a612261cfc8a7687735a140c6c7024
https://git.kernel.org/stable/c/0a25484fe22f621e151367a59a82330a22ac80bc
https://git.kernel.org/stable/c/92090f6ff2acc81e9dd99881dcfb4f8c1bdaabd3