7.8

CVE-2026-89738

usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed

In polled-VBUS mode (board.vbus_pin && board.vbus_polled), probe arms a
self-restarting cycle: at91_vbus_timer() schedules vbus_timer_work, and
at91_vbus_timer_work() calls at91_vbus_update() and re-arms the timer via
mod_timer(). Both recover the same udc through container_of and dereference
it on every iteration.

Neither teardown path cancels this cycle. udc is devm-allocated, so it is
freed after at91udc_remove() returns, and is likewise freed when probe
fails and devres runs. A timer callback or work item that is pending or
running at either point dereferences the freed udc.

Add at91_udc_shutdown_vbus_timer() and call it from at91udc_remove() and
from the usb_add_gadget_udc() failure path in probe; the remaining probe
error paths fail before the timer is armed. timer_shutdown_sync() waits
for a running callback and clears timer->function, which makes the work
handler's mod_timer() a permanent no-op; cancel_work_sync() then drains
any pending or running work whose re-arm attempt now does nothing. The
timer must be shut down first, since cancelling the work alone would let
the timer re-queue it. The guard mirrors probe: in IRQ mode the timer and
work_struct are never initialized.

This does not require a fault; a normal driver unbind can interleave with
an already queued work item.

This issue was found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4037242c4f5ff77afe61bf07ca1e8a99490219e5
Version < a2a602cb1e28d76a5398cec3fa21b0110385f501
Status affected
Version 4037242c4f5ff77afe61bf07ca1e8a99490219e5
Version < 51a311eb97e91ce1aed3005cb71ccb2e30f8cce8
Status affected
Version 4037242c4f5ff77afe61bf07ca1e8a99490219e5
Version < 557ef547d49ff5e6026a4d39bdd3113bd81d7688
Status affected
Version 4037242c4f5ff77afe61bf07ca1e8a99490219e5
Version < c27d13ce4bab80fbdf6523928071b6c24b37606c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.36
Status affected
Version 0
Version < 2.6.36
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a2a602cb1e28d76a5398cec3fa21b0110385f501
https://git.kernel.org/stable/c/51a311eb97e91ce1aed3005cb71ccb2e30f8cce8
https://git.kernel.org/stable/c/557ef547d49ff5e6026a4d39bdd3113bd81d7688
https://git.kernel.org/stable/c/c27d13ce4bab80fbdf6523928071b6c24b37606c