Executive brief
A vulnerability was identified in the Linux kernel's Intel USBIO bridge driver that could lead to a system crash. When a USB device using this driver is disconnected, the system may attempt to access memory that has already been cleared, resulting in a 'use-after-free' error. This typically occurs during the teardown process of the device's software components.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/usb/misc/usbio.c within the usbio_disconnect() function. The root cause is the use of list_for_each_entry_reverse() to iterate through the usbio->cli_list. During iteration, auxiliary_device_uninit() is called, which can drop the final reference and free the struct usbio_client. The iterator then attempts to access the 'prev' pointer of the now-freed client structure. The fix replaces the iterator with list_for_each_entry_safe_reverse(), which caches the next pointer before the current entry is potentially freed. This vulnerability was confirmed via KASAN (Kernel Address Sanitizer) reports.
Affected products
- Linux Linux Kernel Intel USBIO bridge driver
Timeline
- 2026-06-18: other: Patch submitted by Cen Zhang
- 2026-07-08: patched: Committed to stable tree by Greg Kroah-Hartman
- 2026-07-25: disclosed: CVE published