Executive brief
The Linux kernel's HID sony driver contains a use-after-free vulnerability in its cleanup routine for Guitar Hero Live (GHL) dongles. When a GHL dongle is disconnected or the driver is unloaded, a race condition between a periodic timer and USB request cleanup can cause the timer to fire after memory has been freed, potentially leading to system instability or denial of service. This affects systems running the vulnerable kernel version with GHL devices connected.
Technical details
The vulnerability is a use-after-free (UAF) race condition in the HID sony driver's handling of GHL dongle cleanup. The driver arms a periodic timer (ghl_poke_timer) that submits a USB request (ghl_urb); the URB completion callback re-arms the timer. However, sony_remove() deletes the timer via timer_delete_sync() and immediately frees the URB and driver context via usb_free_urb() and devm_kzalloc() cleanup. Since timer_delete_sync() does not block timer re-arming, a URB completion that occurs during the window before the delete finishes can re-arm the timer. After the driver context is freed, the re-armed timer fires on already-freed memory, triggering a use-after-free from timer softirq context. The fix involves poisoning the URB first (usb_poison_urb()) to prevent resubmission, then using timer_shutdown_sync() to drain and block re-arming, before finally freeing memory. This is a disconnect/rmmod race condition reproducible via dummy_hcd emulation.
Affected products
- Linux Linux kernel affecting version next-20260710 and likely other recent versions
Timeline
- 2026-09-11: disclosed: CVE-2026-89625 published
- patched: Fix committed upstream involving usb_poison_urb() and timer_shutdown_sync()