PT-2026-90454 · Linux · Linux
CVE-2026-89738
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: at91 udc: drain polled-VBUS timer/work before udc is freed
In polled-VBUS mode (board.vbus pin && board.vbus polled), probe arms a
self-restarting cycle: at91 vbus timer() schedules vbus timer work, and
at91 vbus timer work() calls at91 vbus update() and re-arms the timer via
mod timer(). Both recover the same udc through container of and dereference
it on every iteration.
Neither teardown path cancels this cycle. udc is devm-allocated, so it is
freed after at91udc remove() returns, and is likewise freed when probe
fails and devres runs. A timer callback or work item that is pending or
running at either point dereferences the freed udc.
Add at91 udc shutdown vbus timer() and call it from at91udc remove() and
from the usb add gadget udc() failure path in probe; the remaining probe
error paths fail before the timer is armed. timer shutdown sync() waits
for a running callback and clears timer->function, which makes the work
handler's mod timer() a permanent no-op; cancel work sync() then drains
any pending or running work whose re-arm attempt now does nothing. The
timer must be shut down first, since cancelling the work alone would let
the timer re-queue it. The guard mirrors probe: in IRQ mode the timer and
work struct are never initialized.
This does not require a fault; a normal driver unbind can interleave with
an already queued work item.
This issue was found by an in-house static analysis tool.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux