Executive brief
The Linux kernel contains a use-after-free vulnerability in the RapidIO Tsi721 bridge device driver's doorbell interrupt handler. When processing doorbell messages, a list iteration bug causes invalid memory to be dereferenced, potentially allowing a local attacker with access to the system to trigger a kernel crash or escalate privileges.
Technical details
The vulnerability exists in drivers/rapidio/devices/tsi721.c in the tsi721_db_dpc() function. The code uses a list_for_each() loop to search for a doorbell entry but declares the "found" flag outside the loop. If the doorbell is not found, the iterator points to invalid memory. More critically, the "found" flag is not reset at the start of each loop iteration, causing all doorbells after the first match to be incorrectly marked as found, leading to use-after-free when the invalid iterator is dereferenced. The fix moves the "found" variable inside the loop and resets it for each iteration. This is a local vector vulnerability requiring no special privileges but affecting kernel stability.
Affected products
- Linux Linux kernel multiple versions up to and including 6.x
Timeline
- 2026-08-28: disclosed
- 2026-05-08: patched: Fix committed upstream; backported to stable branches