CVE-2026-80677

Summary

In the Linux kernel, the following vulnerability has been resolved:

driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()

dev_has_sync_state() reads dev->driver twice without holding device_lock() – once for the NULL check and once to dereference ->sync_state. Some callers only hold device_links_write_lock, which doesn't prevent a concurrent unbind from clearing dev->driver via device_unbind_cleanup().

Fix it by reading dev->driver exactly once with READ_ONCE(), pairing with the WRITE_ONCE() in device_set_driver().

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < 89789e4c141904506163dcb91c7289a074573931affected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < 51b3e1de53ee5b7775c7ff90e67fdb2665fce938affected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < 358697929351f619143f59c6a8a15a4994748b79affected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < 5e79e0180515b31b2e2244dc3d256fd8b5a07021affected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < 860885fcd2611bca8c28dac8b2c1c7ff160f763eaffected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < cc77f0d91e3214e4292208f02a1dc09a31f9aac7affected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < 9b0f4082a09760939588135d60a8e9cc994bfa3eaffected
LinuxLinuxac338acf514e7b578fa9e3742ec2c292323b4c1a < e9506871a8ea304cde48ff4a57226df2aadddae3affected
LinuxLinux6d88283a49425eb469aa60ffebe76539e73c933eaffected
LinuxLinux5.5.13 < 5.6affected
LinuxLinux5.6affected
LinuxLinux0 < 5.6unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References