Executive brief
A vulnerability was identified in the Linux kernel's USB physical layer driver for ISP1301 chips. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized code due to improper memory management when handling USB hardware references. The issue specifically affects systems using certain older hardware configurations that do not use Open Firmware (OF) device trees.
Technical details
A use-after-free vulnerability exists in drivers/usb/phy/phy-isp1301.c within the Linux kernel. The root cause is a reference count imbalance in the isp1301_get_client() helper function; while it correctly incremented the reference count for I2C devices in Open Firmware (OF) cases, it failed to do so for non-OF cases. This leads to a situation where a caller might decrement the reference count unconditionally, potentially freeing the device object while it is still in use. An attacker with local access could exploit this race condition to trigger memory corruption or a kernel panic. Patches have been released across multiple stable kernel branches to ensure the reference count is incremented for non-OF devices.
Affected products
- Linux Linux Kernel 5.10.248 to 5.11; versions prior to 6.13
Timeline
- 2025-12-18: patched: Initial patch authored by Johan Hovold
- 2026-01-23: disclosed: CVE published
References
- https://git.kernel.org/stable/c/03bbdaa4da8c6ea0c8431a5011db188a07822c8a
- https://git.kernel.org/stable/c/43e58abad6c08c5f0943594126ef4cd6559aac0b
- https://git.kernel.org/stable/c/5d3df03f70547d4e3fc10ed4381c052eff51b157
- https://git.kernel.org/stable/c/7501ecfe3e5202490c2d13dc7e181203601fcd69
- https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
- https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3