Executive brief
A vulnerability was identified in the Linux kernel's USB Type-C connector driver. When the driver is removed from the system, a race condition could allow the system to attempt to use memory that has already been freed. This could lead to a system crash or unpredictable behavior during hardware removal or system shutdown.
Technical details
A use-after-free vulnerability exists in drivers/usb/typec/ucsi/ucsi_ccg.c in the Linux kernel. The ucsi_ccg_remove() function calls ucsi_destroy(), which frees the 'ucsi' structure, before calling free_irq(). If a threaded interrupt handler (ccg_irq_handler) is already in flight, it may attempt to access the freed 'ucsi' object via ucsi_notify_common(). The fix reorders the removal path to ensure the interrupt is disabled and freed before the underlying data structures are destroyed. This issue was identified via static analysis.
Affected products
- Linux Linux kernel e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2
Timeline
- 2026-07-25: advisory: CVE-2026-64329 published
- 2026-07-24: patched: Fix committed to stable tree
References
- https://git.kernel.org/stable/c/1a160076d3d0dcd4a98a4599ad96eec0790b099b
- https://git.kernel.org/stable/c/1f0bdc2884b67de337215079bba166df0cdf4ac5
- https://git.kernel.org/stable/c/86c9ee928c4a370e323e432aaf8dca79c4ba7c85
- https://git.kernel.org/stable/c/99381e762273a2410a3f0216000be32b013c0ea9
- https://git.kernel.org/stable/c/c32df11147822d22facee8fa30c2e8971d12f426
- https://git.kernel.org/stable/c/dbb500bad02146b388041877574829016591ddc8
- https://git.kernel.org/stable/c/f1adeb1ff8bef1467d6961059810795d02bbad5d