Executive brief
The Linux kernel's interconnect framework contains a use-after-free vulnerability in the icc_get() and of_icc_get_by_index() functions. When memory allocation fails during path setup, the code incorrectly frees a path object while it still has active references in system data structures, leaving dangling pointers. An attacker can trigger this vulnerability through kernel interfaces, potentially causing a system crash or allowing arbitrary code execution.
Technical details
The vulnerability is a use-after-free (CWE-416) in the Linux kernel's interconnect path management code. When path_find() initializes a path and links its requests into req_list via hlist_add_head(), subsequent kasprintf() allocation failures cause the error handler to call kfree(path) directly instead of the proper cleanup function icc_put(). This leaves stale hlist pointers that are later accessed or modified by traversals in path_find() or icc_set_bw(), triggering KASAN slab-use-after-free reports. The root cause is improper resource cleanup that fails to unlink the path from interconnect node lists before deallocation. The fix requires replacing kfree(path) with icc_put(path) and releasing the icc_lock mutex before calling icc_put() to avoid deadlock. The vulnerability is accessible via debugfs or other kernel interfaces that call icc_get().
Affected products
- Linux Linux kernel affected versions unknown
Timeline
- 2026-09-11: disclosed