Executive brief
A vulnerability was identified in the Linux kernel's RapidIO subsystem, which handles high-performance interconnect communications. Under specific failure conditions during network setup, the system could leave behind a 'dangling pointer,' potentially leading to system instability or crashes. This issue has been resolved by ensuring memory is correctly cleared and pointers are neutralized when a setup failure occurs.
Technical details
A vulnerability in the Linux kernel's RapidIO subsystem (drivers/rapidio/rio-scan.c) was identified where a failure in idtab allocation within rio_scan_alloc_net() could lead to a dangling pointer. Specifically, if the allocation failed, the code previously used rio_free_net(net) before the network was fully registered, and failed to nullify mport->net. This could result in a use-after-free or invalid memory access if the mport structure was subsequently accessed. The fix replaces the incorrect free call with kfree() and explicitly sets mport->net to NULL to prevent dangling pointer references. This is primarily a local stability issue requiring specific hardware/driver initialization failure conditions to trigger.
Affected products
- Linux Linux Kernel All versions prior to the fix in the RapidIO subsystem
Timeline
- 2026-01-21: other: Patch submitted by developer
- 2026-01-31: patched: Patch committed to mainline kernel
- 2026-05-08: disclosed: CVE published
References
- https://git.kernel.org/stable/c/34a4f233df5eef5f1f113b2196142c0568b387f8
- https://git.kernel.org/stable/c/649c2e853608cad0b0cba545555d168e67f094b3
- https://git.kernel.org/stable/c/666183dcdd9ad3b8156a1df7f204f728f720380f
- https://git.kernel.org/stable/c/78812c4fb7ed242d5961bf1337a49070d6487c94
- https://git.kernel.org/stable/c/83e579c2f7f6b1706323d744833b26470049dcc2
- https://git.kernel.org/stable/c/87272e3e70ec4b666885bd520ff77463c11444ef
- https://git.kernel.org/stable/c/e5a732bfe29451e16abf9c6f07ce5948b22f3d59