CVE-2025-71145
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
23/01/2026
Última modificación:
23/01/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: phy: isp1301: fix non-OF device reference imbalance<br />
<br />
A recent change fixing a device reference leak in a UDC driver<br />
introduced a potential use-after-free in the non-OF case as the<br />
isp1301_get_client() helper only increases the reference count for the<br />
returned I2C device in the OF case.<br />
<br />
Increment the reference count also for non-OF so that the caller can<br />
decrement it unconditionally.<br />
<br />
Note that this is inherently racy just as using the returned I2C device<br />
is since nothing is preventing the PHY driver from being unbound while<br />
in use.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/03bbdaa4da8c6ea0c8431a5011db188a07822c8a
- https://git.kernel.org/stable/c/43e58abad6c08c5f0943594126ef4cd6559aac0b
- https://git.kernel.org/stable/c/5d3df03f70547d4e3fc10ed4381c052eff51b157
- https://git.kernel.org/stable/c/7501ecfe3e5202490c2d13dc7e181203601fcd69
- https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
- https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3



