« Volver al listado

CVE-2026-72486

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mailbox: mtk-adsp: fix UAF during device teardown

When the SOF audio driver fails to initialize (e.g. firmware boot timeout), its devres unwind frees the snd_sof_dev object that the mailbox client (mtk-adsp-ipc) reaches via chan->cl->rx_callback. The mtk-adsp-mailbox shutdown clears the mailbox command registers but leaves the IRQ line unmasked, so a late interrupt can still queue a threaded handler after mbox_free_channel() had cleared chan->cl, and mbox_chan_received_data() would then trigger UAF:

The crash was observed roughly three seconds after the failed probe.

Leer descripción completaMostrar menos

disable_irq() in shutdown and enable_irq() in startup. disable_irq() also waits for any in-flight interrupts, so by the time mbox_free_channel() proceeds to clear chan->cl no rx_callback can run.

In addition, request the IRQ with IRQF_NO_AUTOEN so it stays masked between probe and the first client bind — otherwise an early interrupt can crash on chan->cl == NULL in mbox_chan_received_data().

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-use-after-free in sof_ipc3_validate_fw_version
   sof_ipc3_validate_fw_version
   sof_ipc3_do_rx_work
   sof_ipc3_rx_msg
   mt8196_dsp_handle_request
   mtk_adsp_ipc_recv
   mbox_chan_received_data
   mtk_adsp_mbox_isr
   irq_thread_fn
  Freed by task ...:
   kfree
   devres_release_all
   really_probe
   ... (sof-audio-of-mt8196 probe failure)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72486",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "af2dfa96c52d042df5deb29fb6e32d3ff4d76a61",
              "lessThan": "b6337a08a63eef8efcffe3c01d479badda6bbbdb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af2dfa96c52d042df5deb29fb6e32d3ff4d76a61",
              "lessThan": "e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af2dfa96c52d042df5deb29fb6e32d3ff4d76a61",
              "lessThan": "fc6c3deb1d4c0adebf7dee0b8af4082af3f17690",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af2dfa96c52d042df5deb29fb6e32d3ff4d76a61",
              "lessThan": "7d881615fb6373f71fc628b3f00186aeca87a3d5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af2dfa96c52d042df5deb29fb6e32d3ff4d76a61",
              "lessThan": "25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af2dfa96c52d042df5deb29fb6e32d3ff4d76a61",
              "lessThan": "b57d1a40bc43258372fa1f4d39305e093947a262",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/mailbox/mtk-adsp-mailbox.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/mailbox/mtk-adsp-mailbox.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:22.860",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7d881615fb6373f71fc628b3f00186aeca87a3d5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b57d1a40bc43258372fa1f4d39305e093947a262",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6337a08a63eef8efcffe3c01d479badda6bbbdb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fc6c3deb1d4c0adebf7dee0b8af4082af3f17690",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mtk-adsp: fix UAF during device teardown\n\nWhen the SOF audio driver fails to initialize (e.g. firmware boot\ntimeout), its devres unwind frees the snd_sof_dev object that the\nmailbox client (mtk-adsp-ipc) reaches via chan->cl->rx_callback.\nThe mtk-adsp-mailbox shutdown clears the mailbox command registers\nbut leaves the IRQ line unmasked, so a late interrupt can still\nqueue a threaded handler after mbox_free_channel() had cleared\nchan->cl, and mbox_chan_received_data() would then trigger UAF:\n\n  BUG: KASAN: slab-use-after-free in sof_ipc3_validate_fw_version\n   sof_ipc3_validate_fw_version\n   sof_ipc3_do_rx_work\n   sof_ipc3_rx_msg\n   mt8196_dsp_handle_request\n   mtk_adsp_ipc_recv\n   mbox_chan_received_data\n   mtk_adsp_mbox_isr\n   irq_thread_fn\n  Freed by task ...:\n   kfree\n   devres_release_all\n   really_probe\n   ... (sof-audio-of-mt8196 probe failure)\n\nThe crash was observed roughly three seconds after the failed probe.\n\ndisable_irq() in shutdown and enable_irq() in startup. disable_irq()\nalso waits for any in-flight interrupts, so by the time\nmbox_free_channel() proceeds to clear chan->cl no rx_callback can run.\n\nIn addition, request the IRQ with IRQF_NO_AUTOEN so it stays masked\nbetween probe and the first client bind — otherwise an early interrupt\ncan crash on chan->cl == NULL in mbox_chan_received_data()."
    }
  ],
  "lastModified": "2026-08-17T06:19:16.810",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}