7.8

CVE-2026-89938

iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF

In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF

The atlas driver requests its hardware data-ready IRQ with
devm_request_threaded_irq(); its threaded handler queues an irq_work,
atlas_work_handler(), that calls iio_trigger_poll(data->trig).

The IRQ is devm-managed, so free_irq() runs from the devres unwind after
atlas_remove() returns without flushing that irq_work.  Once a buffer is
enabled, conversion-complete IRQs keep firing and queueing it; a pending
irq_work can therefore run after the unwind has freed atlas_data/indio_dev
and the trigger, when atlas_work_handler() derives the atlas_data pointer
via container_of() and dereferences data->trig, a use-after-free.

Call iio_trigger_poll_nested() directly from the threaded handler instead
of bouncing through irq_work.  free_irq() then drains the threaded handler,
closing the window; other iio drivers with a threaded data-ready IRQ do the
same (e.g. bmi270).

This issue was found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7103b99b031cb0ff6979331757bfc4893f37ae9e
Version < f64b437641b5a70c18bb0fd38da2b69d8926c871
Status affected
Version 7103b99b031cb0ff6979331757bfc4893f37ae9e
Version < 91e12b0fbd7047d02bf4ef4dbc491b9ef0159250
Status affected
Version 7103b99b031cb0ff6979331757bfc4893f37ae9e
Version < 2071624c3d0f497ca91da78858e6f30d7112fea6
Status affected
Version 7103b99b031cb0ff6979331757bfc4893f37ae9e
Version < 30b0d44c978bbc857bd68b71dab371805653de70
Status affected
Version 7103b99b031cb0ff6979331757bfc4893f37ae9e
Version < be61c8c6252671ecf1fee0ad90f87669e0be1e20
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.8
Status affected
Version 0
Version < 4.8
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871
https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250
https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6
https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70
https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20