Executive brief
The Linux kernel's RapidIO driver contains a use-after-free vulnerability in device initialization error handling. When RapidIO network device registration fails, a dangling pointer is left pointing to freed memory. A later unregister operation can dereference this freed pointer, potentially causing system crashes or allowing privilege escalation on systems using RapidIO hardware interconnects.
Technical details
A use-after-free vulnerability exists in the RapidIO driver's rio_scan_alloc_net() function. When rio_add_net() fails, the function correctly releases the device via put_device(), which triggers the device release callback and frees the rio_net structure. However, the mport->net pointer is left dangling, pointing to the freed rio_net object. A subsequent mport unregister path can dereference this dangling pointer and attempt to free the same rio_net again, causing a double-free or use-after-free. The fix clears mport->net to NULL in the rio_add_net() failure path. This affects the RapidIO interconnect fabric driver in the Linux kernel; attack vector requires kernel module/driver functionality for RapidIO capable systems.
Affected products
- Linux Linux Kernel multiple (patches applied across stable series 3.x through 7.x)
Timeline
- 2026-09-17: disclosed
- 2026-07-08: patched: Upstream fix committed; backported to stable branches