Description
In the Linux kernel, the following vulnerability has been resolved:

ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove

Three issues arise when the device is removed while a tty session is
still active:

1. UAF of struct ipoctal: the remove callback frees ipoctal via
kfree() while tty ops may still access it. Fix by introducing
kref-based lifetime management — kref is taken in install() when
a tty is opened and released in cleanup() when the tty is finally
destroyed; remove() uses kref_put() instead of kfree().

2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove()
frees xmit_buf via tty_port_free_xmit_buf() while a userspace
process may still hold the tty fd and call write(). Fix by
checking for NULL xmit_buf in ipoctal_write_tty().

3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)
dereferences ipoctal->dev after the ipack_device has been freed
by ipack_device_del(). Fix by caching ipoctal->carrier_owner
during probe() and calling module_put() on the cached pointer
directly in cleanup(), avoiding any access to ipoctal->dev.

Also introduce a "removed" flag in struct ipoctal, set at the start
of __ipoctal_remove(), and checked in every tty op that accesses
hardware resources (port_activate, write_tty, set_termios, hangup,
shutdown). This prevents page faults when devm_ioremap() regions
are unmapped after remove() returns.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash (Denial of Service) / local privilege escalation
Action: Apply Patch
AI Analysis

Impact

This kernel vulnerability arises when the ipack ioctl Octal device is removed while a tty session remains open. The removal callback releases an ipoctal structure that still may be accessed by active tty operations, causing a use‑after‑free. Additional paths lead to a null pointer dereference when the device removes its transmit buffer while a user process can write to the tty and to a second use‑after‑free when cleanup accesses a freed device pointer. The errors can trigger a kernel crash, yielding denial of service, and may be leveraged by an authenticated local user to execute arbitrary code at kernel privilege.

Affected Systems

Affected vendors: Linux for the Linux kernel. All kernel versions before the patch roll‑in fix the bug; exact version ranges are not listed in the data. Systems running any kernel whose source includes the obsolete ipoctal removal logic are vulnerable.

Risk and Exploitability

The simplified EPSS score of less than 1% indicates a very low probability of exploitation, and the exploit is not yet listed in CISA’s KEV catalog. The attack vector is local, requiring the attacker to trigger device removal while a tty session is active. Privilege escalation is possible if kernel memory can be overwritten. The impact score is high due to the potential for kernel panic, but the likely exploitability is low.

Generated by OpenCVE AI on September 19, 2026 at 06:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the fix introduced by the kref-based lifetime management and null check changes.
  • If an upgrade is not immediately possible, avoid removing the affected device while tty sessions are active; ensure all tty processes close before device removal.
  • Monitor and log device removal events in custom kernel builds to detect attempts to remove devices during active tty sessions.

Generated by OpenCVE AI on September 19, 2026 at 06:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove Three issues arise when the device is removed while a tty session is still active: 1. UAF of struct ipoctal: the remove callback frees ipoctal via kfree() while tty ops may still access it. Fix by introducing kref-based lifetime management — kref is taken in install() when a tty is opened and released in cleanup() when the tty is finally destroyed; remove() uses kref_put() instead of kfree(). 2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove() frees xmit_buf via tty_port_free_xmit_buf() while a userspace process may still hold the tty fd and call write(). Fix by checking for NULL xmit_buf in ipoctal_write_tty(). 3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev) dereferences ipoctal->dev after the ipack_device has been freed by ipack_device_del(). Fix by caching ipoctal->carrier_owner during probe() and calling module_put() on the cached pointer directly in cleanup(), avoiding any access to ipoctal->dev. Also introduce a "removed" flag in struct ipoctal, set at the start of __ipoctal_remove(), and checked in every tty op that accesses hardware resources (port_activate, write_tty, set_termios, hangup, shutdown). This prevents page faults when devm_ioremap() regions are unmapped after remove() returns.
Title ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:40.360Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.367

Modified: 2026-09-17T17:17:58.367

Link: CVE-2026-93050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses