CVE-2026-63905
CVE CVE-2026-63905EUVD EUVD-2026-45678Veröffentlicht 2026-07-19T14:55:12.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: Fix use after free bug in vudc_remove due to race condition This patch follows up Zheng Wang's 2023 report of a use-after-free in vudc_remove(). The original thread stalled on Shuah Khan's request for runtime testing of the unplug/unbind path. This patch supplies that testing and keeps Zheng's original fix shape. In vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer(). usbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer(). vudc_remove() can then free the containing struct vudc while the timer is still pending or executing. KASAN confirms the race on an unpatched x86_64 QEMU guest with CONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop that repeatedly writes a socket fd to usbip_sockfd, closes the socket pair, and unbinds/rebinds usbip-vudc.0: BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0 Write of size 8 at addr ffff888001b80740 by task trigger_and_unb/239 Allocated by task 239: vudc_probe+0x4d/0xaa0 Freed by task 239: kfree+0x18f/0x520 device_release_driver_internal+0x388/0x540 unbind_store+0xd9/0x100 This lands in the timer core rather than v_timer() itself because the embedded timer_list is being walked after its containing struct vudc has already been freed. The underlying lifetime bug is the same one Zheng reported. With v_stop_timer() called from vudc_remove() and the timer deleted synchronously, the same harness completed 5000 bind/unbind iterations with no KASAN report.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux b6a0ca11186759ad7045d68a5447b1e89f658384 <d07ed707467ce05ea9c03412d0c5ee9d0fe386a6; patch: 5.10.259; b6a0ca11186759ad7045d68a5447b1e89f658384 <207bf80362df3fce8ebc9723351dcb1bc6d9ed0f; patch: 6.1.176; patch: 6.12.93; b6a0ca11186759ad7045d68a5447b1e89f658384 <88d459e5b5a46da1ef9fd6f52d9439343edeec88; b6a0ca11186759ad7045d68a5447b1e89f658384 <1036ac6148995feaf486014d32bf26bf993c06a9; b6a0ca11186759ad7045d68a5447b1e89f658384 <d96209626a29ea64666be98c30b30ac82e5f1be6; b6a0ca11186759ad7045d68a5447b1e89f658384 <a0638db2340ee053ab0450656a763fd111475e54; patch: 7.1; patch: 6.6.143; patch: 7.0.12; b6a0ca11186759ad7045d68a5447b1e89f658384 <61704e5cf9cd7464b510eb606e7e2978b1160a64; patch: 0; 4.7; patch: 5.15.210; b6a0ca11186759ad7045d68a5447b1e89f658384 <dcc1c90b28b28b7c493547506297e78653f81952; patch: 6.18.35
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.