-

CVE-2026-93050

ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove

In the Linux kernel, the following vulnerability has been resolved:

ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove

Three issues arise when the device is removed while a tty session is
still active:

1. UAF of struct ipoctal: the remove callback frees ipoctal via
   kfree() while tty ops may still access it.  Fix by introducing
   kref-based lifetime management — kref is taken in install() when
   a tty is opened and released in cleanup() when the tty is finally
   destroyed; remove() uses kref_put() instead of kfree().

2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove()
   frees xmit_buf via tty_port_free_xmit_buf() while a userspace
   process may still hold the tty fd and call write().  Fix by
   checking for NULL xmit_buf in ipoctal_write_tty().

3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)
   dereferences ipoctal->dev after the ipack_device has been freed
   by ipack_device_del().  Fix by caching ipoctal->carrier_owner
   during probe() and calling module_put() on the cached pointer
   directly in cleanup(), avoiding any access to ipoctal->dev.

Also introduce a "removed" flag in struct ipoctal, set at the start
of __ipoctal_remove(), and checked in every tty op that accesses
hardware resources (port_activate, write_tty, set_termios, hangup,
shutdown).  This prevents page faults when devm_ioremap() regions
are unmapped after remove() returns.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 05e5027efc9c0bb6d1d04cde279afbafca0a7929
Version < ab5f5b27a340004b92252c6a5f23bf1c6cf3b02a
Status affected
Version 05e5027efc9c0bb6d1d04cde279afbafca0a7929
Version < c92ef8fd834521f0b788e0511976c689fe57c63c
Status affected
Version 05e5027efc9c0bb6d1d04cde279afbafca0a7929
Version < a4613140f01bd0fb9980e2746ed9aaa65a29b5d6
Status affected
Version 05e5027efc9c0bb6d1d04cde279afbafca0a7929
Version < 1a3258e105f711538201bdd2ac2a05b11554eabc
Status affected
Version 05e5027efc9c0bb6d1d04cde279afbafca0a7929
Version < 4a6518be316029650301f2a5e8f0def229b895d9
Status affected
Version 05e5027efc9c0bb6d1d04cde279afbafca0a7929
Version < b6b5d64cb161a28347d64dc3168a636c4abb68d5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.8
Status affected
Version 0
Version < 3.8
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ab5f5b27a340004b92252c6a5f23bf1c6cf3b02a
https://git.kernel.org/stable/c/c92ef8fd834521f0b788e0511976c689fe57c63c
https://git.kernel.org/stable/c/a4613140f01bd0fb9980e2746ed9aaa65a29b5d6
https://git.kernel.org/stable/c/1a3258e105f711538201bdd2ac2a05b11554eabc
https://git.kernel.org/stable/c/4a6518be316029650301f2a5e8f0def229b895d9
https://git.kernel.org/stable/c/b6b5d64cb161a28347d64dc3168a636c4abb68d5