Description
In the Linux kernel, the following vulnerability has been resolved:

interconnect: Fix use after free in icc_get() and of_icc_get_by_index()

In of_icc_get_by_index() and icc_get(), if the dynamic allocation for
path->name fails via kasprintf(), the error handling path directly
calls kfree(path) to free the path object and returns an error.

However, prior to this point, path_find() calls path_init(), which
already links the path's requests into the req_list of the respective
interconnect nodes via hlist_add_head(). Directly invoking kfree(path)
leaves dangling pointers in the hlist. A subsequent call to icc_get()
or icc_set_bw() will traverse or modify these corrupted lists, triggering
a slab use afterfree.

KASAN report showing the vulnerability when reproducing via debugfs:

BUG: KASAN: slab-use-after-free in path_find+0x6f8/0xcfc
Write of size 8 at addr fff000000d43f748 by task sh/1
...
Call trace:
kasan_report+0xac/0xfc
path_find+0x6f8/0xcfc
icc_get+0x148/0x380
icc_get_set+0xf8/0x2d0
...
Freed by task 1:
kfree+0x1a0/0x4a4
icc_get+0x2cc/0x380
icc_get_set+0xf8/0x2d0

Fix this by replacing kfree(path) with the proper teardown function,
icc_put(path), which safely removes the requests from the req_list using
hlist_del() and drops the provider usage references before freeing the
memory.

Additionally, in icc_get(), ensure that the icc_lock mutex is released
prior to calling icc_put(path) to avoid a deadlock, as icc_put()
internally acquires the same lock.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption due to use‑after‑free
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel interconnect subsystem, a failure in allocating a path name causes the path object to be freed with kfree() before the object is properly removed from the interconnect request lists. This leaves dangling pointers in the linked‑list structure, and subsequent calls to functions such as icc_get() or icc_set_bw() traverse or modify those corrupted lists, triggering a slab use‑after‑free and potentially crashing the kernel. The flaw is a data‑structure corruption resulting in kernel memory corruption.

Affected Systems

All Linux kernel implementations that include the interconnect driver and expose the functions icc_get() or of_icc_get_by_index() are affected. The common platform enumeration covers the entire kernel family, indicating that any distribution kernel without the fix is at risk, regardless of version or vendor.

Risk and Exploitability

The CVSS score of 7.8 reflects high severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description does not detail an external attack vector, so it is inferred that exploitation likely requires local or privileged access to invoke the vulnerable interconnect functions, possibly via debugfs or privileged services. The impact is primarily denial of service through kernel crashes, with a potential for privilege escalation only if the attacker can leverage the crash to execute code in kernel mode, which is not explicitly stated in the CVE description.

Generated by OpenCVE AI on September 21, 2026 at 02:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the system kernel to a version that includes the patch replacing kfree() with icc_put() and releasing the icc_lock before the call.
  • If an immediate kernel upgrade cannot be performed, disable the interconnect subsystem or any configuration options that enable the vulnerable functions so that they cannot be triggered.
  • Continuously monitor kernel logs for KASAN or panic messages and stop any affected services until the kernel is updated.

Generated by OpenCVE AI on September 21, 2026 at 02:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() In of_icc_get_by_index() and icc_get(), if the dynamic allocation for path->name fails via kasprintf(), the error handling path directly calls kfree(path) to free the path object and returns an error. However, prior to this point, path_find() calls path_init(), which already links the path's requests into the req_list of the respective interconnect nodes via hlist_add_head(). Directly invoking kfree(path) leaves dangling pointers in the hlist. A subsequent call to icc_get() or icc_set_bw() will traverse or modify these corrupted lists, triggering a slab use afterfree. KASAN report showing the vulnerability when reproducing via debugfs: BUG: KASAN: slab-use-after-free in path_find+0x6f8/0xcfc Write of size 8 at addr fff000000d43f748 by task sh/1 ... Call trace: kasan_report+0xac/0xfc path_find+0x6f8/0xcfc icc_get+0x148/0x380 icc_get_set+0xf8/0x2d0 ... Freed by task 1: kfree+0x1a0/0x4a4 icc_get+0x2cc/0x380 icc_get_set+0xf8/0x2d0 Fix this by replacing kfree(path) with the proper teardown function, icc_put(path), which safely removes the requests from the req_list using hlist_del() and drops the provider usage references before freeing the memory. Additionally, in icc_get(), ensure that the icc_lock mutex is released prior to calling icc_put(path) to avoid a deadlock, as icc_put() internally acquires the same lock.
Title interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:41.755Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-81008

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:09.560

Modified: 2026-09-14T13:18:55.183

Link: CVE-2026-81008

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:59Z

Links: CVE-2026-81008 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference