Executive brief
A race condition vulnerability has been identified in the Linux kernel's Comedi subsystem, which handles data acquisition from various hardware devices. The flaw allows the system to detach a device while data polling requests are still active, leading to a memory error known as a use-after-free. An attacker could exploit this to cause a system crash or potentially gain unauthorized access to sensitive information.
Technical details
A race condition exists in the Linux kernel Comedi subsystem between polling and detaching operations. The vulnerability is a use-after-free (UAF) caused by the `COMEDI_DEVCONFIG` ioctl handler removing the allocated async area while poll requests are still active on the `wait_queue_head`. This occurs because the system failed to verify if tasks were still queued on subdevice wait queues before detaching. An attacker with local access could trigger this UAF by initiating a device detach while concurrent poll entries are being processed. The fix involves refactoring `comedi_device_detach()` to use proper write-locking on `dev->attach_lock` to ensure all subdevices are safe to delete before proceeding.
Affected products
- Linux Linux Kernel 2f3fdcd7ce93 to 017198079551a2a5cf61eae966af3c4b145e1f3b
Timeline
- 2025-07-22: patched: Initial patch developed by Ian Abbott and Jens Axboe
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/017198079551a2a5cf61eae966af3c4b145e1f3b
- https://git.kernel.org/stable/c/0f989f9d05492028afd2bded4b42023c57d8a76e
- https://git.kernel.org/stable/c/35b6fc51c666fc96355be5cd633ed0fe4ccf68b2
- https://git.kernel.org/stable/c/5724e82df4f9a4be62908362c97d522d25de75dd
- https://git.kernel.org/stable/c/5c4a2ffcbd052c69bbf4680677d4c4eaa5a252d4
- https://git.kernel.org/stable/c/71ca60d2e631cf9c63bcbc7017961c61ff04e419
- https://git.kernel.org/stable/c/cd4286123d6948ff638ea9cd5818ae4796d5d252