CVE-2026-89625
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind<br />
<br />
For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer:<br />
ghl_magic_poke() (the timer callback) submits sc->ghl_urb, and the URB<br />
completion ghl_magic_poke_cb() re-arms the timer with mod_timer().<br />
<br />
sony_remove() drained the timer with timer_delete_sync() and then freed<br />
the URB with usb_free_urb():<br />
<br />
timer_delete_sync(&sc->ghl_poke_timer);<br />
usb_free_urb(sc->ghl_urb);<br />
<br />
timer_delete_sync() does not block re-arming, and while the URB is in<br />
flight the timer is not pending, so the sync delete is a no-op. A URB<br />
completion that runs after the delete re-arms the timer, and usb_free_urb()<br />
only drops a reference -- it does not kill an in-flight URB. sc is<br />
allocated with devm_kzalloc() and freed once sony_remove() returns, so the<br />
re-armed ghl_poke_timer (embedded in sc) then fires on freed memory, a<br />
use-after-free from timer softirq. This is a disconnect/rmmod race.<br />
<br />
Poison the URB first, then shut the timer down, before freeing the URB.<br />
usb_poison_urb() kills any in-flight URB and permanently rejects further<br />
submissions, so a poke timer that is still pending cannot re-submit the<br />
URB from ghl_magic_poke() in the window before timer_shutdown_sync() runs.<br />
usb_kill_urb() would not suffice: it only cancels the in-flight URB and<br />
leaves it submittable once it returns, so the pending timer could<br />
re-submit it and put a fresh URB in flight over the freed sc.<br />
timer_shutdown_sync() then drains any last callback and blocks re-arming.<br />
The probe error path is unaffected: it is only reached before the timer<br />
is armed.<br />
<br />
Reproduced under KASAN on next-20260710 via dummy_hcd + raw-gadget<br />
emulation of the GHL PS4 dongle (VID 0x1430 / PID 0x07bb): hid-sony binds<br />
and arms the poke timer, the poke URB is held in flight, the driver is<br />
unbound (freeing sc), then the URB is released. The completion re-arms the<br />
timer on the freed sc, and the re-armed timer fires ~8 s later:<br />
<br />
BUG: KASAN: slab-use-after-free in ghl_magic_poke+0x98/0xb0<br />
Read of size 8 at addr ffff88810b02fd50 by task swapper/0/0<br />
ghl_magic_poke+0x98/0xb0<br />
call_timer_fn+0x35/0x2b0<br />
__run_timers+0x69c/0x9a0<br />
run_timer_softirq+0x173/0x2a0<br />
Allocated by task 169: sony_probe<br />
Freed by task 338: devres_release_group


