Executive brief
A vulnerability was identified in the Linux kernel's GPIO aggregator component, which is used to manage General Purpose Input/Output pins. A flaw in how the system cleans up memory during an error could allow a local attacker to trigger a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and availability.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/gpio/gpio-aggregator.c within the Linux kernel. The root cause is an incorrect cleanup sequence in the gpio_aggregator_activate() function: the code frees 'aggr->lookups->dev_id' before calling gpiod_remove_lookup_table(). If a concurrent thread calls gpiod_find() during this window, it may iterate through the lookup table and attempt to dereference the already-freed 'dev_id' pointer during a strcmp() operation. This race condition requires local access to trigger and can result in a kernel panic (DoS) or potentially arbitrary code execution. The fix involves reversing the cleanup order to ensure the entry is removed from the lookup table before its associated memory is freed.
Affected products
- Linux Linux Kernel 6.16 to 6.18.34, 7.0.11, 7.1
Timeline
- 2026-05-20: disclosed: Initial patch submitted by Bartosz Golaszewski
- 2026-06-01: patched: Patch committed to stable trees
- 2026-07-19: advisory: CVE published to NVD