7.8
CVE-2026-89763
- EPSS 0.12%
- Veröffentlicht 11.09.2026 19:47:04
- Zuletzt bearbeitet 21.09.2026 14:17:26
- Erkennungen
KEYS: trusted: Fix TPM teardown ordering
In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: Fix TPM teardown ordering
trusted_tpm_exit() drops the TPM chip reference and frees the digest
array before unregistering the trusted key type. key_type_lookup()
holds key_types_sem for reading until the key operation finishes, while
unregister_key_type() takes it for writing. It therefore provides the
synchronization point that must precede backend teardown.
The current order permits this interleaving:
CPU 0 CPU 1
trusted_tpm_exit() key_type_lookup("trusted")
put_device(&chip->dev) trusted_tpm_seal()
kfree(digests) pcrlock()
unregister_key_type() tpm_pcr_extend(..., digests)
CPU 1 can consequently dereference the freed digest array. The chip can
also be released before callbacks stop using it.
KASAN reported:
BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200
Read of size 2 at addr ffff88810872d000 by task poc/89
Call Trace:
tpm_pcr_extend+0x1f0/0x200
pcrlock+0x42/0x70 [trusted]
trusted_tpm_seal+0x1b6/0x570 [trusted]
trusted_instantiate+0x293/0x340 [trusted]
__key_instantiate_and_link+0xb2/0x2b0
__key_create_or_update+0x61e/0xb50
__do_sys_add_key+0x1b8/0x310
Allocated by task 88:
__kmalloc_noprof+0x1a7/0x490
do_one_initcall+0xa1/0x390
do_init_module+0x2df/0x840
Freed by task 90:
kfree+0x131/0x3c0
trusted_tpm_exit+0x59/0xa0 [trusted]
__do_sys_delete_module+0x346/0x510
Move unregister_key_type() before releasing either resource. This stops
new lookups and waits for in-flight key operations to finish before the
backend state is destroyed.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400
Version <
3d67b4acbfc7af331d887a8efc04bef6573b8a7a
Status
affected
Version
0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400
Version <
753c978f2400f9783eb524842a975d3ac950d511
Status
affected
Version
0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400
Version <
2f7541afbc57fe9d26769a22c31d8ce8790c9a19
Status
affected
Version
0b6cf6b97b7ef1fa3c7fefab0cac897a1c4a3400
Version <
5e2d672280d97d83de43031d93761b12dadd7b8a
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.1
Status
affected
Version
0
Version <
5.1
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/753c978f2400f9783eb524842a975d3ac950d511
https://git.kernel.org/stable/c/2f7541afbc57fe9d26769a22c31d8ce8790c9a19
https://git.kernel.org/stable/c/5e2d672280d97d83de43031d93761b12dadd7b8a
https://git.kernel.org/stable/c/3d67b4acbfc7af331d887a8efc04bef6573b8a7a