HIGH Introduced in 5.3
s390/cio DriverOverride UAF
CVE-2026-53117
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: s390/cio: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]
02KernelScan AI Analysis
Risk summary
A use-after-free vulnerability exists in the s390 Channel I/O (CIO) subsystem's CSS bus driver_override handling. When a driver is probed via __driver_attach(), the bus match() callback accesses the driver_override field without holding the device lock, creating a race window where the string can be freed concurrently. This is limited to s390/IBM Z systems and requires local access with sufficient privileges to manipulate driver bindings.
Vulnerability analysis
The root cause is that the s390 CIO CSS bus implemented its own driver_override field (const char *driver_override in struct subchannel) and custom sysfs store/show handlers. The css_bus_match() function accessed sch->driver_override without holding the device lock. Since __driver_attach() calls the bus match() callback intentionally without the device lock, a concurrent write to driver_override (via the sysfs store handler, which calls driver_set_override() and frees the old string) can race with the match() read, resulting in a use-after-free on the driver_override string. The fix removes the custom driver_override field and sysfs attribute entirely, instead setting .driver_override = true on the bus_type struct and using the generic device_match_driver_override() helper, which uses the driver-core's properly locked infrastructure (the generic driver_override is stored in struct device and accessed under the device lock by the core). Attack surface is local to s390 hardware, requiring the ability to write to the driver_override sysfs attribute (typically requires root or CAP_SYS_ADMIN) while concurrent driver probing occurs.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 5.3 | 6.6.141 | c4295487124f |
| 7.0 | 5.3 | 7.0.10 | b660ba045b2b |
| mainline | 5.3 | 7.1 | ac4d8bb6e2e1 |
| 6.12 | 5.3 | 6.12.91 | 106d594711e9 |
| 6.18 | 5.3 | 6.18.33 | 2081957d8c32 |