CVE-2026-68357

Summary

In the Linux kernel, the following vulnerability has been resolved:

watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()

When a watchdog governor is unregistered, it updates existing watchdog devices that were using this governor by falling back to default_gov.

If the governor being unregistered is currently set as default_gov, the default_gov is never cleared. This leads to 2 use-after-free issues:

  1. New watchdog devices registered after this point will inherit the dangling default_gov.
  2. Existing watchdog devices using the unregistered governor will have their wdd->gov reassigned to the dangling default_gov.

Fix the UAF by clearing default_gov if it matches the governor being unregistered.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < b9ae33faa96bdec6bc60e4c5f8f53786182e4207affected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 472ec1e34ff0bb26379805cae808f658cce58c35affected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 7a2ee3ec6f208307eca1119a343c7b5d39c03708affected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 2e47b91b9b4020fcc01def14d6b6556d66074cf4affected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 0ca252720f0e38411cfec3431db9bb1aed0a412caffected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 7d1658b066de30f4b23afc14814d22416a971e6eaffected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 7993d626983cc58fbde9607333cfd2d57725c197affected
LinuxLinuxda0d12ff2b829a35e9921918e925d79497b82bef < 7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661affected
LinuxLinux4.9affected
LinuxLinux0 < 4.9unaffected
LinuxLinux5.10.265 <= 5.10.*unaffected
LinuxLinux5.15.216 <= 5.15.*unaffected
LinuxLinux6.1.183 <= 6.1.*unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References