Junglewise Threat Intelligence

CVE-2026-80622: Linux kernel tlclk driver use-after-free in cleanup

CVE-2026-80622 · Severity: high · CVSS 7.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's tlclk (telecom clock) driver contains a use-after-free vulnerability in its module cleanup routine. When the module is unloaded, the kernel may free memory while user-space processes still hold file descriptors to the device, or while timers and waitqueues are still active. An attacker with local access could exploit this to cause kernel memory corruption, denial of service, or potentially gain elevated code execution privileges.

Technical details

The vulnerability is a use-after-free race condition in the tlclk_cleanup() function. The root causes are: (1) the file_operations structure lacks the .owner field, allowing premature module unloading while user-space processes maintain active file descriptors; and (2) tlclk_cleanup() frees alarm_events memory before ensuring blocked readers in the waitqueue are awakened and the switchover_timer has fully completed execution. An attacker with local access can exploit this by holding an open file descriptor to the tlclk device while the module is unloaded, resulting in memory corruption. The fix sets .owner = THIS_MODULE in tlclk_fops, adds wake_up_all() to unblock waiters, and moves timer_delete_sync() and release_region() before kfree(alarm_events) to ensure proper cleanup sequencing. Patches are available in the Linux kernel stable branches.

Affected products

  • Linux Linux kernel Multiple kernel versions; patched in stable branches

Timeline

  • 2026-08-28: disclosed: CVE-2026-80622 published
  • 2026-05-03: patched: Fix committed upstream by James Kim
  • 2026-07-24: patched: Fix merged to stable branches by Greg Kroah-Hartman

References

Related threats