Junglewise Threat Intelligence

CVE-2026-74575: Linux kernel Thunderbolt XDomain use-after-free on disconnect

CVE-2026-74575 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Thunderbolt subsystem manages connections between computers over Thunderbolt cables. A race condition in the XDomain (cross-domain) disconnect code can cause the kernel to use memory after it has been freed, potentially leading to a system crash or kernel panic. This affects systems with Thunderbolt ports that connect to external devices.

Technical details

A use-after-free vulnerability exists in the Thunderbolt XDomain implementation due to a race condition between delayed work queue operations and device removal. The tb_xdp_handle_request() function (running on system_wq) queues delayed work via queue_delayed_work(), while concurrently tb_xdomain_remove() calls cancel_delayed_work_sync() and tb_xdomain_unregister() frees the xdomain object. Since these paths are no longer serialized after commit 559c1e1e0134, if queue_delayed_work() executes after cancel_delayed_work_sync() but before the object is freed, the delayed work fires on freed memory. The fix adds mutual exclusion via an xd->removing flag and xd->lock mutex: the remove path sets the flag under lock before calling stop_handshake(), while all queue sites check the flag while holding the same lock. Patches are available in Linux kernel stable trees.

Affected products

  • Linux Linux kernel Multiple stable versions (see kernel.org stable branches)

Timeline

  • 2026-08-15: disclosed
  • 2026-05-28: patched: Upstream fix commit 2c5d2d3c3f70cde2565d7b279b544893a2035842
  • 2026-05-27: other: Original author patch submission

References

Related threats