CVE-2026-89763

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> KEYS: trusted: Fix TPM teardown ordering<br /> <br /> trusted_tpm_exit() drops the TPM chip reference and frees the digest<br /> array before unregistering the trusted key type. key_type_lookup()<br /> holds key_types_sem for reading until the key operation finishes, while<br /> unregister_key_type() takes it for writing. It therefore provides the<br /> synchronization point that must precede backend teardown.<br /> <br /> The current order permits this interleaving:<br /> <br /> CPU 0 CPU 1<br /> trusted_tpm_exit() key_type_lookup("trusted")<br /> put_device(&amp;chip-&gt;dev) trusted_tpm_seal()<br /> kfree(digests) pcrlock()<br /> unregister_key_type() tpm_pcr_extend(..., digests)<br /> <br /> CPU 1 can consequently dereference the freed digest array. The chip can<br /> also be released before callbacks stop using it.<br /> <br /> KASAN reported:<br /> <br /> BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200<br /> Read of size 2 at addr ffff88810872d000 by task poc/89<br /> Call Trace:<br /> tpm_pcr_extend+0x1f0/0x200<br /> pcrlock+0x42/0x70 [trusted]<br /> trusted_tpm_seal+0x1b6/0x570 [trusted]<br /> trusted_instantiate+0x293/0x340 [trusted]<br /> __key_instantiate_and_link+0xb2/0x2b0<br /> __key_create_or_update+0x61e/0xb50<br /> __do_sys_add_key+0x1b8/0x310<br /> Allocated by task 88:<br /> __kmalloc_noprof+0x1a7/0x490<br /> do_one_initcall+0xa1/0x390<br /> do_init_module+0x2df/0x840<br /> Freed by task 90:<br /> kfree+0x131/0x3c0<br /> trusted_tpm_exit+0x59/0xa0 [trusted]<br /> __do_sys_delete_module+0x346/0x510<br /> <br /> Move unregister_key_type() before releasing either resource. This stops<br /> new lookups and waits for in-flight key operations to finish before the<br /> backend state is destroyed.