CVE-2026-89763
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
KEYS: trusted: Fix TPM teardown ordering<br />
<br />
trusted_tpm_exit() drops the TPM chip reference and frees the digest<br />
array before unregistering the trusted key type. key_type_lookup()<br />
holds key_types_sem for reading until the key operation finishes, while<br />
unregister_key_type() takes it for writing. It therefore provides the<br />
synchronization point that must precede backend teardown.<br />
<br />
The current order permits this interleaving:<br />
<br />
CPU 0 CPU 1<br />
trusted_tpm_exit() key_type_lookup("trusted")<br />
put_device(&chip->dev) trusted_tpm_seal()<br />
kfree(digests) pcrlock()<br />
unregister_key_type() tpm_pcr_extend(..., digests)<br />
<br />
CPU 1 can consequently dereference the freed digest array. The chip can<br />
also be released before callbacks stop using it.<br />
<br />
KASAN reported:<br />
<br />
BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200<br />
Read of size 2 at addr ffff88810872d000 by task poc/89<br />
Call Trace:<br />
tpm_pcr_extend+0x1f0/0x200<br />
pcrlock+0x42/0x70 [trusted]<br />
trusted_tpm_seal+0x1b6/0x570 [trusted]<br />
trusted_instantiate+0x293/0x340 [trusted]<br />
__key_instantiate_and_link+0xb2/0x2b0<br />
__key_create_or_update+0x61e/0xb50<br />
__do_sys_add_key+0x1b8/0x310<br />
Allocated by task 88:<br />
__kmalloc_noprof+0x1a7/0x490<br />
do_one_initcall+0xa1/0x390<br />
do_init_module+0x2df/0x840<br />
Freed by task 90:<br />
kfree+0x131/0x3c0<br />
trusted_tpm_exit+0x59/0xa0 [trusted]<br />
__do_sys_delete_module+0x346/0x510<br />
<br />
Move unregister_key_type() before releasing either resource. This stops<br />
new lookups and waits for in-flight key operations to finish before the<br />
backend state is destroyed.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH


