Executive brief
A vulnerability was identified in the Linux kernel's Texas Instruments PRUSS driver, which manages Programmable Real-Time Unit subsystems used in industrial communication. A technical error in how the system handles memory during hardware setup could allow a local attacker to cause a system crash or potentially execute unauthorized code. This impact could lead to a complete loss of system availability or unauthorized access to sensitive data on affected industrial or embedded devices.
Technical details
A double free vulnerability exists in the Linux kernel within the `drivers/soc/ti/pruss.c` component. The root cause is located in the `pruss_clk_mux_setup()` function, where `devm_add_action_or_reset()` is used to register a cleanup handler. On an error path, `devm_add_action_or_reset()` triggers the cleanup function `pruss_of_free_clk_provider()`, which calls `of_node_put()`. However, the calling function also executes `of_node_put()` upon receiving the error return, leading to a double free of the same node pointer. A local attacker with low privileges could exploit this to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. Patches have been released across multiple stable kernel branches to ensure the function returns immediately after the reset action.
Affected products
- Linux Linux kernel 5.10 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-01-13: other: Patch submitted by developer
- 2026-05-06: disclosed
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/04dbbb18cc9c8795c9ff47d8994bc03ebfef9d68
- https://git.kernel.org/stable/c/24c40076e3bc3d73c839c886d6bda1da6c4d9b93
- https://git.kernel.org/stable/c/69aa67c1e22d13e9aad4b08c86304ad8e743dcab
- https://git.kernel.org/stable/c/80db65d4acfb9ff12d00172aed39ea8b98261aad
- https://git.kernel.org/stable/c/818cf66d91c8ef09b01664a12d5f4ea786d64396
- https://git.kernel.org/stable/c/b7db9953c2f8da37de498198623b05b46f8e2ca0
- https://git.kernel.org/stable/c/dbda01bf2dfe5af33163e1e5fca1b82b619c2803