7

CVE-2026-93054

uio: Fix stale info pointer in failed registration path

In the Linux kernel, the following vulnerability has been resolved:

uio: Fix stale info pointer in failed registration path

After device_add(), the UIO device is visible to userspace and /dev/uioX
can be opened. If a later setup step fails, __uio_register_device()
unwinds the device but leaves idev->info pointing at the caller-owned
struct uio_info.

That is unsafe when an opener races with the failed registration path.
The open file keeps a reference to the uio_device, while the caller sees
registration failure and may free its struct uio_info. Later file
operations can then follow idev->info and dereference freed memory.

Handle post-device_add() failures like unregister: remove UIO attributes
while the info pointer is still valid, then clear idev->info under
info_lock and wake existing waiters/async users before removing the
device and minor. This makes already-open file descriptors observe the
same "device gone" state as normal uio_unregister_device().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < 63eaa7663335d482a8825c231213e312cacea567
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < df4faf65194ec6c315a59be4c6749eaeb3009243
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < 506b43dde5f9ac0068b1360e6b5dbee07fda59fb
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < 15340b00e665af805523b08515294a1aa1778151
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < 234156f6c6d9ec35dc47abbcc3adc3c79fc6a5ac
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < 16695e9059d80ea6661e8399064b0c01f641dd8c
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < ec5bd6731183eb6f619140c9bef2ee11ed818c20
Status affected
Version a93e7b331568227500186a465fee3c2cb5dffd1f
Version < 67b6fc084b034a91c3ec7907a3fed89a2450f30b
Status affected
Version 085d735c858934e5d5bfaedb1fc98bd9135e6ff1
Status affected
Version 4.14.100
Version < 4.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.18
Status affected
Version 0
Version < 4.18
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/63eaa7663335d482a8825c231213e312cacea567
https://git.kernel.org/stable/c/df4faf65194ec6c315a59be4c6749eaeb3009243
https://git.kernel.org/stable/c/506b43dde5f9ac0068b1360e6b5dbee07fda59fb
https://git.kernel.org/stable/c/15340b00e665af805523b08515294a1aa1778151
https://git.kernel.org/stable/c/234156f6c6d9ec35dc47abbcc3adc3c79fc6a5ac
https://git.kernel.org/stable/c/16695e9059d80ea6661e8399064b0c01f641dd8c
https://git.kernel.org/stable/c/ec5bd6731183eb6f619140c9bef2ee11ed818c20
https://git.kernel.org/stable/c/67b6fc084b034a91c3ec7907a3fed89a2450f30b