Description
In the Linux kernel, the following vulnerability has been resolved:

xhci: dbgtty: Fix unregister on tty_register_driver() failure

If tty_register_driver() fails, it drops the reference, but fails to set
the global dbc_tty_driver to NULL, causing the unregister to be called
again when module exits.

On module unload dbc_tty_exit() only gates its cleanup on the driver
pointer being non-NULL, so it operates on the already-freed driver:

module_init(xhci_hcd_init)
xhci_hcd_init()
xhci_dbc_init() [return value ignored]
dbc_tty_init()
tty_register_driver() fails
tty_driver_kref_put() -> driver freed
(dbc_tty_driver left dangling)
...
module_exit(xhci_hcd_fini)
xhci_hcd_fini()
xhci_dbc_exit()
dbc_tty_exit()
if (dbc_tty_driver) -> true (dangling)
tty_unregister_driver() -> use-after-free
Published: 2026-09-09
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free caused by improper driver cleanup that can crash the kernel and, based on the description, potentially enable privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw occurs in the Linux kernel’s XHCI USB controller subsystem where the debug TTY driver registers and then fails. The failure causes a global driver pointer to remain dangling while the driver object is freed. During module unload, the cleanup routine attempts to unregister the dangling driver, resulting in a use‑after‑free in kernel space. This can corrupt memory, trigger a kernel panic, and, as the driver owns kernel memory, it is inferred that an attacker who can load or unload the module could gain elevated privileges.

Affected Systems

All Linux kernel installations that include the XHCI debug TTY driver and have not incorporated the upstream patch are affected. No specific kernel version range is provided, so any mainline kernel lacking the commit that fixes the dangling pointer is vulnerable. Distributions shipping a default kernel without the patch inherit the flaw.

Risk and Exploitability

The CVSS score is not supplied, but a use‑after‑free in kernel space is normally high severity. The EPSS score is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely local, requiring the attacker to have the ability to load or unload kernel modules. Although direct proof of privilege escalation is not in the text, the nature of the flaw suggests that exploitation could lead to kernel‑level code execution or crash.

Generated by OpenCVE AI on September 9, 2026 at 18:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the upstream patch for the XHCI debug TTY driver; the commit that resolves the dangling pointer is available in recent mainline releases.
  • If an upgrade cannot be applied immediately, disable or unload the XHCI debug TTY module before system reboot to avoid the use‑after‑free during module unload. This can be done by removing the module from init files or disabling its automatic loading.
  • Enable kernel hardening features such as CONFIG_SLAB_FREELIST_RANDOM and CONFIG_KASLR as a temporary countermeasure; these settings make exploitation of use‑after‑free conditions harder but do not fix the underlying bug.

Generated by OpenCVE AI on September 9, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xhci: dbgtty: Fix unregister on tty_register_driver() failure If tty_register_driver() fails, it drops the reference, but fails to set the global dbc_tty_driver to NULL, causing the unregister to be called again when module exits. On module unload dbc_tty_exit() only gates its cleanup on the driver pointer being non-NULL, so it operates on the already-freed driver: module_init(xhci_hcd_init) xhci_hcd_init() xhci_dbc_init() [return value ignored] dbc_tty_init() tty_register_driver() fails tty_driver_kref_put() -> driver freed (dbc_tty_driver left dangling) ... module_exit(xhci_hcd_fini) xhci_hcd_fini() xhci_dbc_exit() dbc_tty_exit() if (dbc_tty_driver) -> true (dangling) tty_unregister_driver() -> use-after-free
Title xhci: dbgtty: Fix unregister on tty_register_driver() failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-09T16:19:43.538Z

Reserved: 2026-08-26T14:34:25.801Z

Link: CVE-2026-80923

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T17:17:47.507

Modified: 2026-09-09T17:17:47.507

Link: CVE-2026-80923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:15:06Z

Weaknesses

No weakness.