CVE-2026-80923

Summary

In the Linux kernel, the following vulnerability has been resolved:

xhci: dbgtty: Fix unregister on tty_register_driver() failure

If tty_register_driver() fails, it drops the reference, but fails to set the global dbc_tty_driver to NULL, causing the unregister to be called again when module exits.

On module unload dbc_tty_exit() only gates its cleanup on the driver pointer being non-NULL, so it operates on the already-freed driver:

module_init(xhci_hcd_init)
  xhci_hcd_init()
    xhci_dbc_init()                       [return value ignored]
      dbc_tty_init()
        tty_register_driver() fails
          tty_driver_kref_put()           -> driver freed
          (dbc_tty_driver left dangling)
...
module_exit(xhci_hcd_fini)
  xhci_hcd_fini()
    xhci_dbc_exit()
      dbc_tty_exit()
        if (dbc_tty_driver)               -> true (dangling)
          tty_unregister_driver()         -> use-after-free

Affected Software

VendorProductVersion RangeStatus
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < 01b7bc0938061f2fd46e0094f6483d8c6c02f7d3affected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < 43635ff6401ca0e0ed21875379eeded921321525affected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < eaca2814f32b9872a332326324b9e83e01f156d2affected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < 943f976c93e70563b132f5585ff68b08c89641a2affected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < 0d0faf3cc44c4d86fc6faf5cea972c0fbe00b922affected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < 33ed35ca629477f57e0dd1d77d6df96cf5a9eb55affected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < 0e469b94fbba8eb03666da41dd1082b793c50c1aaffected
LinuxLinux4521f16139409cdf9462c7325d43454462cff6c3 < a916fa66a43e10f63198b6ce978badffc678821aaffected
LinuxLinux5.9affected
LinuxLinux0 < 5.9unaffected
LinuxLinux5.15.220 <= 5.15.*unaffected
LinuxLinux6.1.187 <= 6.1.*unaffected
LinuxLinux6.6.156 <= 6.6.*unaffected
LinuxLinux6.12.108 <= 6.12.*unaffected
LinuxLinux6.18.49 <= 6.18.*unaffected
LinuxLinux7.1.13 <= 7.1.*unaffected
LinuxLinux7.2.3 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References