Executive brief
A vulnerability in the Linux kernel's Greybus subsystem could allow a local user to crash the system. The issue occurs when a user attempts to write data to a device that has already been disconnected, leading to a kernel panic. This results in a complete loss of system availability, requiring a reboot to restore operations.
Technical details
A use-after-free (UAF) vulnerability exists in the Greybus 'raw' driver (drivers/staging/greybus/raw.c) within the Linux kernel. The vulnerability is triggered when a write operation is initiated on a character device after the underlying connection has been destroyed by the disconnect function. Specifically, 'gb_connection_destroy' frees the connection object, but 'raw_write' may still attempt to use this freed pointer in 'gb_operation_sync'. This race condition or lack of synchronization leads to a NULL pointer dereference or UAF, resulting in a kernel panic. The fix introduces a read-write semaphore ('disconnect_lock') to synchronize access between the write and disconnect paths.
Affected products
- Linux Linux Kernel 4.9 to 7.0.10
Timeline
- 2026-03-24: other: Patch authored
- 2026-06-24: disclosed: CVE published