« Volver al listado

CVE-2026-90001

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

HID: bpf: serialize device reference release in struct_ops destroy path

__hid_bpf_ops_destroy_device() and hid_bpf_unreg() can race on the same registration reference, double-putting struct hid_device and freeing it while hid_destroy_device() still uses it. Serialize the remove/NULL decision under hdev->bpf.prog_list_lock so exactly one path releases each registration reference: unreg re-checks ops->hdev under the lock and returns without putting when the destroy path already cleared it; all put_device() calls happen after the lock is dropped, which is safe because a concurrent unreg then observes ops->hdev == NULL under the lock.

Leer descripción completaMostrar menos

Background: each successful attach (hid_bpf_ops_reg) acquires one device reference (hid_get_device()). Two paths can release it:

The coordination handshake (e->hdev = NULL on the destroy side vs "if (!hdev) return" on the unreg side) is a TOCTOU check: the two paths run under different lock domains (rcu_read_lock vs prog_list_lock), so a concurrent unreg can read ops->hdev as non-NULL, block on prog_list_lock, and then proceed while the destroy traversal executes - both paths then drop the same reference. The refcount reaches zero legitimately (each decrement is individually valid), so no refcount_t saturation fires: the device is simply freed while the transport is still inside hid_destroy_device(), and subsequent teardown touches freed memory.

The fix serializes the remove/NULL decision under prog_list_lock on both sides and moves the destroy-side puts outside the lock. With the lock held, plain reads/writes of ops->hdev are sufficient; no READ_ONCE/WRITE_ONCE are added, keeping the patch minimal.

Unlocked-read safety: the unlocked read of ops->hdev at the top of hid_bpf_unreg() cannot touch a freed device, because the unreg path itself still holds this registration's reference (released only by its own hid_put_device() after the lock is dropped), and a destroy traversal that already cleared ops->hdev makes the lock-internal re-check return early without any put. At most one of the two paths releases each registration reference.

Detalles técnicos trazas, registros y código del informe original
- device destruction: hid_destroy_device() -> hid_bpf_destroy_device()
  -> __hid_bpf_ops_destroy_device(), which walks hdev->bpf.prog_list
  under rcu_read_lock() and drops one reference per attached program;
- BPF link release: bpf map delete (no BPF_F_LINK) synchronously calls
  st_ops->unreg() -> hid_bpf_unreg(), which drops the reference for
  its own registration.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de race condition en kernel Linux (AV:L, PR:L) que permite escalada de privilegios mediante double-free en HID-BPF. Impacto: DoS por corrupción de memoria y crash del sistema.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90001",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ebc0d8093e8c97de459615438edefad1a4ac352c",
              "lessThan": "401359684620145be710de97b87e1a47abfe1459",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ebc0d8093e8c97de459615438edefad1a4ac352c",
              "lessThan": "c7f927aa8b55008ed5ea0814313d5dad771dcf3c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ebc0d8093e8c97de459615438edefad1a4ac352c",
              "lessThan": "bfb7939788f3c8dd080a4dd81e38d625b35d194e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ebc0d8093e8c97de459615438edefad1a4ac352c",
              "lessThan": "9cdc7e6dc7a99ad7311ad5e7c145f2b9ce4e24b0",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hid/bpf/hid_bpf_struct_ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hid/bpf/hid_bpf_struct_ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:11.700",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/401359684620145be710de97b87e1a47abfe1459",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9cdc7e6dc7a99ad7311ad5e7c145f2b9ce4e24b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfb7939788f3c8dd080a4dd81e38d625b35d194e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c7f927aa8b55008ed5ea0814313d5dad771dcf3c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: bpf: serialize device reference release in struct_ops destroy path\n\n__hid_bpf_ops_destroy_device() and hid_bpf_unreg() can race on the\nsame registration reference, double-putting struct hid_device and\nfreeing it while hid_destroy_device() still uses it.  Serialize the\nremove/NULL decision under hdev->bpf.prog_list_lock so exactly one\npath releases each registration reference: unreg re-checks ops->hdev\nunder the lock and returns without putting when the destroy path\nalready cleared it; all put_device() calls happen after the lock is\ndropped, which is safe because a concurrent unreg then observes\nops->hdev == NULL under the lock.\n\nBackground: each successful attach (hid_bpf_ops_reg) acquires one\ndevice reference (hid_get_device()).  Two paths can release it:\n\n- device destruction: hid_destroy_device() -> hid_bpf_destroy_device()\n  -> __hid_bpf_ops_destroy_device(), which walks hdev->bpf.prog_list\n  under rcu_read_lock() and drops one reference per attached program;\n- BPF link release: bpf map delete (no BPF_F_LINK) synchronously calls\n  st_ops->unreg() -> hid_bpf_unreg(), which drops the reference for\n  its own registration.\n\nThe coordination handshake (e->hdev = NULL on the destroy side vs\n\"if (!hdev) return\" on the unreg side) is a TOCTOU check: the two\npaths run under different lock domains (rcu_read_lock vs\nprog_list_lock), so a concurrent unreg can read ops->hdev as\nnon-NULL, block on prog_list_lock, and then proceed while the\ndestroy traversal executes - both paths then drop the same\nreference.  The refcount reaches zero legitimately (each decrement\nis individually valid), so no refcount_t saturation fires: the\ndevice is simply freed while the transport is still inside\nhid_destroy_device(), and subsequent teardown touches freed memory.\n\nThe fix serializes the remove/NULL decision under prog_list_lock on\nboth sides and moves the destroy-side puts outside the lock.  With\nthe lock held, plain reads/writes of ops->hdev are sufficient; no\nREAD_ONCE/WRITE_ONCE are added, keeping the patch minimal.\n\nUnlocked-read safety: the unlocked read of ops->hdev at the top of\nhid_bpf_unreg() cannot touch a freed device, because the unreg path\nitself still holds this registration's reference (released only by\nits own hid_put_device() after the lock is dropped), and a destroy\ntraversal that already cleared ops->hdev makes the lock-internal\nre-check return early without any put.  At most one of the two\npaths releases each registration reference."
    }
  ],
  "lastModified": "2026-09-16T15:18:23.880",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}