« Volver al listado

CVE-2026-93050

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove

Three issues arise when the device is removed while a tty session is still active:

Also introduce a "removed" flag in struct ipoctal, set at the start of __ipoctal_remove(), and checked in every tty op that accesses hardware resources (port_activate, write_tty, set_termios, hangup, shutdown). This prevents page faults when devm_ioremap() regions are unmapped after remove() returns.

Detalles técnicos trazas, registros y código del informe original
1. UAF of struct ipoctal: the remove callback frees ipoctal via
   kfree() while tty ops may still access it.  Fix by introducing
   kref-based lifetime management — kref is taken in install() when
   a tty is opened and released in cleanup() when the tty is finally
   destroyed; remove() uses kref_put() instead of kfree().

2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove()
   frees xmit_buf via tty_port_free_xmit_buf() while a userspace
   process may still hold the tty fd and call write().  Fix by
   checking for NULL xmit_buf in ipoctal_write_tty().

3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)
   dereferences ipoctal->dev after the ipack_device has been freed
   by ipack_device_del().  Fix by caching ipoctal->carrier_owner
   during probe() and calling module_put() on the cached pointer
   directly in cleanup(), avoiding any access to ipoctal->dev.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93050",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "05e5027efc9c0bb6d1d04cde279afbafca0a7929",
              "lessThan": "ab5f5b27a340004b92252c6a5f23bf1c6cf3b02a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05e5027efc9c0bb6d1d04cde279afbafca0a7929",
              "lessThan": "c92ef8fd834521f0b788e0511976c689fe57c63c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05e5027efc9c0bb6d1d04cde279afbafca0a7929",
              "lessThan": "a4613140f01bd0fb9980e2746ed9aaa65a29b5d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05e5027efc9c0bb6d1d04cde279afbafca0a7929",
              "lessThan": "1a3258e105f711538201bdd2ac2a05b11554eabc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05e5027efc9c0bb6d1d04cde279afbafca0a7929",
              "lessThan": "4a6518be316029650301f2a5e8f0def229b895d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05e5027efc9c0bb6d1d04cde279afbafca0a7929",
              "lessThan": "b6b5d64cb161a28347d64dc3168a636c4abb68d5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/ipack/devices/ipoctal.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/ipack/devices/ipoctal.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:58.367",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1a3258e105f711538201bdd2ac2a05b11554eabc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4a6518be316029650301f2a5e8f0def229b895d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4613140f01bd0fb9980e2746ed9aaa65a29b5d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab5f5b27a340004b92252c6a5f23bf1c6cf3b02a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6b5d64cb161a28347d64dc3168a636c4abb68d5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c92ef8fd834521f0b788e0511976c689fe57c63c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove\n\nThree issues arise when the device is removed while a tty session is\nstill active:\n\n1. UAF of struct ipoctal: the remove callback frees ipoctal via\n   kfree() while tty ops may still access it.  Fix by introducing\n   kref-based lifetime management — kref is taken in install() when\n   a tty is opened and released in cleanup() when the tty is finally\n   destroyed; remove() uses kref_put() instead of kfree().\n\n2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove()\n   frees xmit_buf via tty_port_free_xmit_buf() while a userspace\n   process may still hold the tty fd and call write().  Fix by\n   checking for NULL xmit_buf in ipoctal_write_tty().\n\n3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)\n   dereferences ipoctal->dev after the ipack_device has been freed\n   by ipack_device_del().  Fix by caching ipoctal->carrier_owner\n   during probe() and calling module_put() on the cached pointer\n   directly in cleanup(), avoiding any access to ipoctal->dev.\n\nAlso introduce a \"removed\" flag in struct ipoctal, set at the start\nof __ipoctal_remove(), and checked in every tty op that accesses\nhardware resources (port_activate, write_tty, set_termios, hangup,\nshutdown).  This prevents page faults when devm_ioremap() regions\nare unmapped after remove() returns."
    }
  ],
  "lastModified": "2026-09-17T17:17:58.367",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}