KernelScan.io

HIGH Introduced in 4.9

greybus raw CdevClose UAF

CVE-2026-53025

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: greybus: raw: fix use-after-free on cdev close This addresses a use-after-free bug when a raw bundle is disconnected but its chardev is still opened by an application. When the application releases the cdev, it causes the following panic when init on free is enabled (CONFIG_INIT_ON_FREE_DEFAULT_ON=y): refcount_t: underflow; use-after-free. WARNING: CPU: 0 PID: 139 at lib/refcount.c:28 refcount_warn_saturate+0xd0/0x130 ... Call Trace: <TASK> cdev_put+0x18/0x30 __fput+0x255/0x2a0 __x64_sys_close+0x3d/0x80 do_syscall_64+0xa4/0x290 entry_SYSCALL_64_after_hwframe+0x77/0x7f The cdev is contained in the "gb_raw" structure, which is freed in the disconnect operation. When the cdev is released at a later time, cdev_put gets an address that points to freed memory. To fix this use-after-free, convert the struct device from a pointer to being embedded, that makes the lifetime of the cdev and of this device the same. Then, use cdev_device_add, which guarantees that the device won't be released until all references to the cdev have been released. Finally, delegate the freeing of the structure to the device release function, instead of freeing immediately in the disconnect callback.

02

Engine v0.3.0

Risk summary

A use-after-free vulnerability in the Linux kernel Greybus raw character device driver allows a local user who has opened the raw chardev to trigger memory corruption when the underlying USB Greybus bundle is disconnected while the file descriptor remains open. When the application subsequently closes the file descriptor, the kernel's cdev reference counting operates on already-freed memory, potentially leading to privilege escalation or kernel panic. Exploitation requires a local user with access to the Greybus raw chardev and the ability to race device disconnection with file descriptor close.

Affecteddrivers/staging/greybus/raw.c (Greybus raw protocol driver)

Vulnerability analysis

The root cause is a lifetime management bug in drivers/staging/greybus/raw.c. The gb_raw structure (which embeds the cdev) was freed immediately in the gb_raw_disconnect() callback via kfree(raw), without accounting for any open file descriptors that still hold a reference to the cdev. When an application later closes its file descriptor, cdev_put() dereferences the kobject embedded in the cdev, which now points to freed memory, causing a use-after-free. The fix converts the struct device from a pointer (device_create/device_destroy pattern) to being embedded directly in gb_raw, then uses cdev_device_add()/cdev_device_del() which ties the cdev lifetime to the device reference count. The disconnect callback now calls put_device() instead of kfree(), and actual memory freeing is delegated to a raw_dev_release() callback that fires only after all cdev references are dropped. This ensures the gb_raw structure remains valid until the last file descriptor is closed. The attack surface requires local access to the Greybus raw chardev (typically accessible to users with USB device access) and a USB device disconnect event while the chardev is open — a race condition between disconnect and close.

03

BranchIntroducedFixed inPatch commit
mainline4.97.1983cc2c7efbc
7.04.97.0.10ef2d97c15b19