Executive brief
The Linux kernel's Thunderbolt subsystem manages connections between computers over Thunderbolt cables. A race condition in the XDomain (cross-domain) disconnect code can cause the kernel to use memory after it has been freed, potentially leading to a system crash or kernel panic. This affects systems with Thunderbolt ports that connect to external devices.
Technical details
A use-after-free vulnerability exists in the Thunderbolt XDomain implementation due to a race condition between delayed work queue operations and device removal. The tb_xdp_handle_request() function (running on system_wq) queues delayed work via queue_delayed_work(), while concurrently tb_xdomain_remove() calls cancel_delayed_work_sync() and tb_xdomain_unregister() frees the xdomain object. Since these paths are no longer serialized after commit 559c1e1e0134, if queue_delayed_work() executes after cancel_delayed_work_sync() but before the object is freed, the delayed work fires on freed memory. The fix adds mutual exclusion via an xd->removing flag and xd->lock mutex: the remove path sets the flag under lock before calling stop_handshake(), while all queue sites check the flag while holding the same lock. Patches are available in Linux kernel stable trees.
Affected products
- Linux Linux kernel Multiple stable versions (see kernel.org stable branches)
Timeline
- 2026-08-15: disclosed
- 2026-05-28: patched: Upstream fix commit 2c5d2d3c3f70cde2565d7b279b544893a2035842
- 2026-05-27: other: Original author patch submission