Executive brief
The Linux kernel's iPhone USB Ethernet driver (ipheth) contains a use-after-free vulnerability in its carrier detection mechanism. When a USB device is disconnected while a data transmission is in flight, the carrier-check work can be re-armed after the driver has attempted to stop it, leading to memory corruption when the network interface is freed. This can cause system crashes or undefined behavior.
Technical details
The vulnerability is a use-after-free (CWE-416) in the ipheth USB network driver. The root cause is that ipheth_sndbulk_callback() re-arms the delayed carrier-check work on any non-zero URB status, without checking whether the interface is up. When ipheth_disconnect() is called, it drains the work via cancel_delayed_work_sync() but then calls usb_kill_urb(), which completes in-flight URBs with -ENOENT and re-triggers the callback, re-arming the work. If the interface is already down, unregister_netdev() does not call ipheth_close(), leaving the work armed until free_netdev() frees the netdev structure, at which point ipheth_carrier_check_work() dereferences freed memory. Attack vector is local (requires physical USB device or USB gadget emulation); no privilege escalation or exploit code was developed. The patch ties work scheduling to interface state (open/close) rather than URB completion status.
Affected products
- Linux Linux kernel linux-next (next-20260731) and later
Timeline
- 2026-08-22: disclosed
- other: Patch available as part of kernel fix