Executive brief
The Linux kernel's SATA driver for SL82C105 storage controllers contains a use-after-free vulnerability in the bridge revision detection logic. An attacker with local access can potentially trigger a system crash or execute arbitrary code by exploiting this memory safety issue during device initialization.
Technical details
The vulnerability is a use-after-free in the sl82c105_bridge_revision() function in drivers/ata/pata_sl82c105.c. The function calls pci_get_slot() to obtain a reference to a PCI bridge device, then calls pci_dev_put() to drop that reference, but subsequently attempts to read the revision field from the freed bridge structure. The root cause stems from commit 44c10138fd4b which replaced a configuration-space read with direct access to the cached revision field but failed to reorder the operations. An attacker with local access to a system with an SL82C105 controller can trigger this by manipulating device driver initialization. The fix reads the revision field before dropping the reference via pci_dev_put().
Affected products
- Linux Linux kernel Linux 2.6.11 through 7.x (all branches affected; patched in upstream and stable trees)
Timeline
- 2026-09-03: disclosed: CVE-2026-80732 published on NVD
- 2026-08-19: patched: Upstream commit 7700a31039cdc6715cb6cce7e7a664ee4e945f67 merged into stable trees