CVE-2026-80622
CVE CVE-2026-80622EUVD EUVD-2026-67498Veröffentlicht 2026-08-28T06:48:41.000ZZuletzt geändert 2026-08-29T06:21:27.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: char: tlclk: fix use-after-free in tlclk_cleanup() This patch improves the module cleanup process in the tlclk driver to prevent potential use-after-free and race conditions. Currently, the file_operations structure does not specify the .owner field, which could allow the module to be unloaded while user-space processes are still interacting with the device. Additionally, the tlclk_cleanup() function frees the alarm_events memory before ensuring that blocked processes in the waitqueue are fully awakened and that the switchover_timer has completed. To address these cases, this patch: - Sets '.owner = THIS_MODULE' in tlclk_fops to safely defer module unloading while the device is in use. - Updates tlclk_cleanup() to explicitly wake up all blocked readers (wake_up_all), properly release hardware I/O regions, and safely delete the timer (timer_delete_sync) prior to freeing memory.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 5.10.261; 1a80ba88273097933f93b1f40537337416798c70 <bbf003b7794d6ad6f939fdd29f1f1bde8ac554c1; patch: 0; 1a80ba88273097933f93b1f40537337416798c70 <96902299a22d126ef5eb3f45cd5d8ceea9e6a735; 1a80ba88273097933f93b1f40537337416798c70 <42223445607a9a5df3cb1c4729abfe3a5085e7ce; patch: 6.12.97; patch: 5.15.212; 1a80ba88273097933f93b1f40537337416798c70 <166dd1d5265e067459e674c11688919901813ec2; patch: 6.6.145; 2.6.15; 1a80ba88273097933f93b1f40537337416798c70 <c3f0cd76561ae611c2d247ee96dfd559e4197cb7; 1a80ba88273097933f93b1f40537337416798c70 <764723bd67a6c8f53a8d8309211fb039e2ebcf49; patch: 7.2; patch: 6.18.40; 1a80ba88273097933f93b1f40537337416798c70 <09d8d2a46a9ec9ff728f3159a174a2ab25dd0f0a; 1a80ba88273097933f93b1f40537337416798c70 <3d5e4cc0d9dce79b0429da3134ac7b072ab9009f; patch: 6.1.178; patch: 7.1.5
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.