CVE-2026-74441
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: typec: ucsi: Fix race condition and ordering in port unregistration<br />
<br />
A synchronization issue exists during port unregistration where pending<br />
partner work items can race against workqueue destruction, leading to<br />
use-after-free conditions:<br />
<br />
cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed<br />
BUG: kernel NULL pointer dereference, address: 0000000000000000<br />
RIP: 0010:__queue_work+0x83/0x4a0<br />
Call Trace:<br />
<br />
__cfi_delayed_work_timer_fn+0x10/0x10<br />
run_timer_softirq+0x3b6/0xbd0<br />
sched_clock_cpu+0xc/0x110<br />
irq_exit_rcu+0x18d/0x330<br />
fred_sysvec_apic_timer_interrupt+0x5e/0x80<br />
<br />
Fix this by ensuring strict ordering and proper serialization during<br />
teardown:<br />
<br />
1. Move ucsi_unregister_partner() to the beginning of the teardown<br />
sequence and protect it under the connector mutex lock.<br />
2. Ensure all pending partner tasks are explicitly flushed and finished<br />
before the workqueue is destroyed.<br />
3. Switch from mod_delayed_work() to a cancel_delayed_work() and<br />
queue_delayed_work() sequence. This guarantees that items currently marked<br />
as pending won&#39;t be scheduled an additional time, preventing a double<br />
release of resources which leads to the following crash:<br />
<br />
Oops: general protection fault, probably for non-canonical address<br />
0xdead000000000122: 0000 [#1] SMP NOPTI<br />
Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker<br />
RIP: 0010:ucsi_poll_worker+0x65/0x1e0<br />
Call Trace:<br />
<br />
process_scheduled_works+0x218/0x6d0<br />
worker_thread+0x188/0x3f0<br />
__cfi_worker_thread+0x10/0x10<br />
kthread+0x226/0x2a0<br />
<br />
To ensure these rules are applied identically across both the normal<br />
teardown and the ucsi_init() error paths, consolidate the cleanup logic<br />
into a new helper, ucsi_unregister_port().
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/07f8aaffee705e552c1f723ac8bf7eb137ad59c2
- https://git.kernel.org/stable/c/11483d80267db97fbe49f2df66385434256cc3b0
- https://git.kernel.org/stable/c/3f7b3728dd9011c915cbeaea77274ebe8366550d
- https://git.kernel.org/stable/c/7aa7d4bf9d3fa9a6a47b640ad103ab433b7ff261
- https://git.kernel.org/stable/c/bc7a0f721123ea260a42f1ded06dab844ba49434



