Executive brief
A vulnerability exists in the Linux kernel's as102 USB driver, which is used for certain digital TV receiver hardware. A race condition allows a local attacker to trigger a system crash or potentially execute unauthorized code by interacting with the device driver while it is being initialized or disconnected. This could lead to a full system compromise or a denial-of-service state.
Technical details
A race condition exists in the as102_usb driver within the as102_usb_probe() function. When a USB device is registered via usb_register_dev(), a userspace process can open the device file descriptor before the driver completes its error-handling path. If an error occurs subsequently, the driver calls usb_deregister_dev() and immediately frees the as102_dev_t structure. However, the open file descriptor remains valid until closed, at which point as102_release() is triggered, leading to a use-after-free (UAF) and a double-free (DFB) of the already released memory. The fix involves deferring the memory deallocation to the .release() callback to ensure all references are dropped before the structure is freed.
Affected products
- Linux Linux Kernel up to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
References
- https://git.kernel.org/stable/c/07ceb444c8f627cf863864d4274b5a77769725ed
- https://git.kernel.org/stable/c/09e9206008b887aa553733bd915d73131071a086
- https://git.kernel.org/stable/c/0d36653a3a821e5a974798adb347b3ea09332914
- https://git.kernel.org/stable/c/25d500cf391e384356a612b85cf60b353ad3cd0c
- https://git.kernel.org/stable/c/2eeae47a438694408189138048a786be99954032
- https://git.kernel.org/stable/c/582fbecb3756330006fe1950762412a68c2cacd2
- https://git.kernel.org/stable/c/7e5aedf6059cba2a669d86caeaf5a51f33ec85a1