« Volver al listado

CVE-2026-80563

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind

The "trigger" debugfs file has a hand-rolled ->write handler (trigger_write()) that dereferences the per-device gpio_la_poll_priv. The file is created with debugfs_create_file_unsafe(), and the handler never takes a debugfs reference. Nothing keeps the object alive while the handler runs.

priv is allocated with devm_kzalloc(). devres frees it when the platform device is unbound. debugfs_create_file_unsafe() installs no full_proxy wrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not wait for an in-flight trigger_write().

Leer descripción completaMostrar menos

The blob_lock taken there does not help, because trigger_write() never takes it. A write that races an unbind therefore writes into freed memory:

The race is reachable by root via /sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind.

Create "trigger" with debugfs_create_file() instead. Its full_proxy wrapper makes debugfs_remove_recursive() drain any in-flight ->write before it returns.

The use-after-free is confirmed under KASAN with a minimal reproducer of the same debugfs_create_file_unsafe() plus devm_kzalloc() pattern (available on request); it produces a slab-use-after-free write in the handler.

Detalles técnicos trazas, registros y código del informe original
  trigger_write()                  gpio_la_poll_remove()
    priv = m->private
    buf = memdup_user()  [may sleep]
                                     mutex_lock(&priv->blob_lock)
                                     debugfs_remove_recursive()  [no wait]
                                     mutex_unlock(&priv->blob_lock)
                                   (remove returns; devres frees priv)
    priv->trig_data = buf   <-- use-after-free write
    priv->trig_len  = count

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80563",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7828b7bbbf2074dd7dd14d87f50bc5ce9036d692",
              "lessThan": "49a1ebb1ef2c8ada300c174b65273810abb4e326",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7828b7bbbf2074dd7dd14d87f50bc5ce9036d692",
              "lessThan": "23e9f32c0c7d2043e39655cff5ee3ddf29a43f80",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7828b7bbbf2074dd7dd14d87f50bc5ce9036d692",
              "lessThan": "24bef4918f6ab806260476e2f93d8f791fd17449",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7828b7bbbf2074dd7dd14d87f50bc5ce9036d692",
              "lessThan": "44f3468a0aef1aabdad551898ab7cfa2a9d20e99",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpio/gpio-sloppy-logic-analyzer.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.46",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpio/gpio-sloppy-logic-analyzer.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-26T15:17:11.310",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/23e9f32c0c7d2043e39655cff5ee3ddf29a43f80",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/24bef4918f6ab806260476e2f93d8f791fd17449",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/44f3468a0aef1aabdad551898ab7cfa2a9d20e99",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/49a1ebb1ef2c8ada300c174b65273810abb4e326",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind\n\nThe \"trigger\" debugfs file has a hand-rolled ->write handler\n(trigger_write()) that dereferences the per-device gpio_la_poll_priv. The\nfile is created with debugfs_create_file_unsafe(), and the handler never\ntakes a debugfs reference. Nothing keeps the object alive while the\nhandler runs.\n\npriv is allocated with devm_kzalloc(). devres frees it when the platform\ndevice is unbound. debugfs_create_file_unsafe() installs no full_proxy\nwrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not\nwait for an in-flight trigger_write(). The blob_lock taken there does not\nhelp, because trigger_write() never takes it. A write that races an unbind\ntherefore writes into freed memory:\n\n  trigger_write()                  gpio_la_poll_remove()\n    priv = m->private\n    buf = memdup_user()  [may sleep]\n                                     mutex_lock(&priv->blob_lock)\n                                     debugfs_remove_recursive()  [no wait]\n                                     mutex_unlock(&priv->blob_lock)\n                                   (remove returns; devres frees priv)\n    priv->trig_data = buf   <-- use-after-free write\n    priv->trig_len  = count\n\nThe race is reachable by root via\n/sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind.\n\nCreate \"trigger\" with debugfs_create_file() instead. Its full_proxy\nwrapper makes debugfs_remove_recursive() drain any in-flight ->write\nbefore it returns.\n\nThe use-after-free is confirmed under KASAN with a minimal reproducer of\nthe same debugfs_create_file_unsafe() plus devm_kzalloc() pattern\n(available on request); it produces a slab-use-after-free write in the\nhandler."
    }
  ],
  "lastModified": "2026-08-26T15:17:11.310",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}