CVE-2026-63905
In the Linux kernel, the following vulnerability has been resolved:
usbip: vudc: Fix use after free bug in vudc_remove due to race condition
This patch follows up Zheng Wang's 2023 report of a use-after-free in vudc_remove(). The original thread stalled on Shuah Khan's request for runtime testing of the unplug/unbind path. This patch supplies that testing and keeps Zheng's original fix shape.
In vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer(). usbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer(). vudc_remove() can then free the containing struct vudc while the timer is still pending or executing.
Leer descripción completaMostrar menos
KASAN confirms the race on an unpatched x86_64 QEMU guest with CONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop that repeatedly writes a socket fd to usbip_sockfd, closes the socket pair, and unbinds/rebinds usbip-vudc.0:
This lands in the timer core rather than v_timer() itself because the embedded timer_list is being walked after its containing struct vudc has already been freed. The underlying lifetime bug is the same one Zheng reported.
With v_stop_timer() called from vudc_remove() and the timer deleted synchronously, the same harness completed 5000 bind/unbind iterations with no KASAN report.
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0
Write of size 8 at addr ffff888001b80740 by task trigger_and_unb/239
Allocated by task 239:
vudc_probe+0x4d/0xaa0
Freed by task 239:
kfree+0x18f/0x520
device_release_driver_internal+0x388/0x540
unbind_store+0xd9/0x100CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1036ac6148995feaf486014d32bf26bf993c06a9
- https://git.kernel.org/stable/c/207bf80362df3fce8ebc9723351dcb1bc6d9ed0f
- https://git.kernel.org/stable/c/61704e5cf9cd7464b510eb606e7e2978b1160a64
- https://git.kernel.org/stable/c/88d459e5b5a46da1ef9fd6f52d9439343edeec88
- https://git.kernel.org/stable/c/a0638db2340ee053ab0450656a763fd111475e54
- https://git.kernel.org/stable/c/d07ed707467ce05ea9c03412d0c5ee9d0fe386a6
- https://git.kernel.org/stable/c/d96209626a29ea64666be98c30b30ac82e5f1be6
- https://git.kernel.org/stable/c/dcc1c90b28b28b7c493547506297e78653f81952
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-63905",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "61704e5cf9cd7464b510eb606e7e2978b1160a64",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "dcc1c90b28b28b7c493547506297e78653f81952",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "1036ac6148995feaf486014d32bf26bf993c06a9",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "a0638db2340ee053ab0450656a763fd111475e54",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "d07ed707467ce05ea9c03412d0c5ee9d0fe386a6",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "88d459e5b5a46da1ef9fd6f52d9439343edeec88",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "207bf80362df3fce8ebc9723351dcb1bc6d9ed0f",
"versionType": "git"
},
{
"status": "affected",
"version": "b6a0ca11186759ad7045d68a5447b1e89f658384",
"lessThan": "d96209626a29ea64666be98c30b30ac82e5f1be6",
"versionType": "git"
}
],
"programFiles": [
"drivers/usb/usbip/vudc_dev.c",
"drivers/usb/usbip/vudc_transfer.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/usb/usbip/vudc_dev.c",
"drivers/usb/usbip/vudc_transfer.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:08.260",
"references": [
{
"url": "https://git.kernel.org/stable/c/1036ac6148995feaf486014d32bf26bf993c06a9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/207bf80362df3fce8ebc9723351dcb1bc6d9ed0f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/61704e5cf9cd7464b510eb606e7e2978b1160a64",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/88d459e5b5a46da1ef9fd6f52d9439343edeec88",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a0638db2340ee053ab0450656a763fd111475e54",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d07ed707467ce05ea9c03412d0c5ee9d0fe386a6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d96209626a29ea64666be98c30b30ac82e5f1be6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dcc1c90b28b28b7c493547506297e78653f81952",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbip: vudc: Fix use after free bug in vudc_remove due to race condition\n\nThis patch follows up Zheng Wang's 2023 report of a use-after-free in\nvudc_remove(). The original thread stalled on Shuah Khan's request for\nruntime testing of the unplug/unbind path. This patch supplies that\ntesting and keeps Zheng's original fix shape.\n\nIn vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer().\nusbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer().\nvudc_remove() can then free the containing struct vudc while the timer is\nstill pending or executing.\n\nKASAN confirms the race on an unpatched x86_64 QEMU guest with\nCONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop\nthat repeatedly writes a socket fd to usbip_sockfd, closes the socket\npair, and unbinds/rebinds usbip-vudc.0:\n\n BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0\n Write of size 8 at addr ffff888001b80740 by task trigger_and_unb/239\n Allocated by task 239:\n vudc_probe+0x4d/0xaa0\n Freed by task 239:\n kfree+0x18f/0x520\n device_release_driver_internal+0x388/0x540\n unbind_store+0xd9/0x100\n\nThis lands in the timer core rather than v_timer() itself because the\nembedded timer_list is being walked after its containing struct vudc has\nalready been freed. The underlying lifetime bug is the same one Zheng\nreported.\n\nWith v_stop_timer() called from vudc_remove() and the timer deleted\nsynchronously, the same harness completed 5000 bind/unbind iterations\nwith no KASAN report."
}
],
"lastModified": "2026-07-27T17:44:23.777",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}