CVE-2026-64233
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/07/2026
Última modificación:
24/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind<br />
<br />
uvc_function_bind() walks &opts->extension_units twice without holding<br />
opts->lock:<br />
<br />
- directly, for the iExtension string-descriptor fixup loop;<br />
- indirectly, four times via uvc_copy_descriptors() (once per speed),<br />
where the helper iterates uvc->desc.extension_units (which aliases<br />
&opts->extension_units) to size and emit XU descriptors.<br />
<br />
The configfs side (uvcg_extension_make / uvcg_extension_drop, in<br />
drivers/usb/gadget/function/uvc_configfs.c) takes opts->lock around its<br />
list_add_tail / list_del operations. A privileged userspace process<br />
that holds the configfs subtree open and writes the gadget UDC name<br />
to bind the function while concurrently rmdir()&#39;ing an extensions<br />
subdir can race uvcg_extension_drop() against the bind-time list walks<br />
and dereference a freed struct uvcg_extension.<br />
<br />
Hold opts->lock from the start of the XU string-descriptor fixup<br />
through the last uvc_copy_descriptors() call, releasing on the<br />
descriptor-error path via a new error_unlock label that drops the<br />
lock before falling through to the existing error label. This<br />
matches the locking discipline of the configfs callbacks and removes<br />
the only remaining unsynchronised reader of the XU list during bind.<br />
<br />
Reachability: only privileged processes that can mount configfs and<br />
write to gadget UDC files can trigger the race, so this is a<br />
correctness fix rather than a security boundary.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2c9e0905ef7e69f7b814cd709613f6b3b5b98805
- https://git.kernel.org/stable/c/5f1b9cff88982e2a2053d8b1fd983f7ccb9f03cc
- https://git.kernel.org/stable/c/68aa70648b625fa684bc0b71bbfd905f4943ca20
- https://git.kernel.org/stable/c/caec0145e5974e85fe5192fc6a6f5aa1a98f82a6
- https://git.kernel.org/stable/c/e15c414092b3c24610cc771e481a723b0f645eca



