Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74441

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: typec: ucsi: Fix race condition and ordering in port unregistration<br /> <br /> A synchronization issue exists during port unregistration where pending<br /> partner work items can race against workqueue destruction, leading to<br /> use-after-free conditions:<br /> <br /> cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed<br /> BUG: kernel NULL pointer dereference, address: 0000000000000000<br /> RIP: 0010:__queue_work+0x83/0x4a0<br /> Call Trace:<br /> <br /> __cfi_delayed_work_timer_fn+0x10/0x10<br /> run_timer_softirq+0x3b6/0xbd0<br /> sched_clock_cpu+0xc/0x110<br /> irq_exit_rcu+0x18d/0x330<br /> fred_sysvec_apic_timer_interrupt+0x5e/0x80<br /> <br /> Fix this by ensuring strict ordering and proper serialization during<br /> teardown:<br /> <br /> 1. Move ucsi_unregister_partner() to the beginning of the teardown<br /> sequence and protect it under the connector mutex lock.<br /> 2. Ensure all pending partner tasks are explicitly flushed and finished<br /> before the workqueue is destroyed.<br /> 3. Switch from mod_delayed_work() to a cancel_delayed_work() and<br /> queue_delayed_work() sequence. This guarantees that items currently marked<br /> as pending won&amp;#39;t be scheduled an additional time, preventing a double<br /> release of resources which leads to the following crash:<br /> <br /> Oops: general protection fault, probably for non-canonical address<br /> 0xdead000000000122: 0000 [#1] SMP NOPTI<br /> Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker<br /> RIP: 0010:ucsi_poll_worker+0x65/0x1e0<br /> Call Trace:<br /> <br /> process_scheduled_works+0x218/0x6d0<br /> worker_thread+0x188/0x3f0<br /> __cfi_worker_thread+0x10/0x10<br /> kthread+0x226/0x2a0<br /> <br /> To ensure these rules are applied identically across both the normal<br /> teardown and the ucsi_init() error paths, consolidate the cleanup logic<br /> into a new helper, ucsi_unregister_port().

Impacto