Executive brief
A vulnerability was identified in the Linux kernel's ChromeOS Embedded Controller (cros_ec) driver. This issue occurs during the hardware initialization process, where internal data structures are prematurely exposed to other parts of the system before they are fully ready. If the initialization fails, it can lead to a system crash or unpredictable behavior, potentially impacting the stability and availability of devices using this driver.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/mfd/cros_ec_dev.c within the Linux kernel. The root cause is the premature invocation of dev_set_drvdata() during the ec_device_probe() function. If the probe subsequently fails, cros_ec_class_release() frees the cros_ec_dev structure, but sub-drivers (such as cros_ec_typec) can still retrieve and attempt to dereference the now-stale pointer via the platform device. This can be triggered during device discovery or deferred probing, leading to a kernel oops or memory corruption. The fix involves delaying dev_set_drvdata() until all initialization steps have succeeded.
Affected products
- Linux Linux Kernel 1c1d152cc5ac to 8b2c1d41bc36c100b38ce5ee6def246c527eaf8a
Timeline
- 2026-04-27: other: Patch developed and signed off by maintainers
- 2026-07-24: patched: Committed to stable kernel trees
- 2026-07-25: disclosed: CVE published and NVD record created
References
- https://git.kernel.org/stable/c/24522713034d521ea4b5f5f36342e2b2f7e73bd6
- https://git.kernel.org/stable/c/257203d83204b192d1265a916b42ca0d499bb117
- https://git.kernel.org/stable/c/729ae27dc2503a7c1f92da1859efb45da03e4fa0
- https://git.kernel.org/stable/c/8b2c1d41bc36c100b38ce5ee6def246c527eaf8a
- https://git.kernel.org/stable/c/b5f41d5bf08e7b1b14fa0bd640975e6d78dc006d
- https://git.kernel.org/stable/c/ed2941e5db016a0c600b25f1972620e6e223d9fa
- https://git.kernel.org/stable/c/f7e81dc181d9fe8ab977158042cd193e8cc12091