Description
In the Linux kernel, the following vulnerability has been resolved:

uio: Fix stale info pointer in failed registration path

After device_add(), the UIO device is visible to userspace and /dev/uioX
can be opened. If a later setup step fails, __uio_register_device()
unwinds the device but leaves idev->info pointing at the caller-owned
struct uio_info.

That is unsafe when an opener races with the failed registration path.
The open file keeps a reference to the uio_device, while the caller sees
registration failure and may free its struct uio_info. Later file
operations can then follow idev->info and dereference freed memory.

Handle post-device_add() failures like unregister: remove UIO attributes
while the info pointer is still valid, then clear idev->info under
info_lock and wake existing waiters/async users before removing the
device and minor. This makes already-open file descriptors observe the
same "device gone" state as normal uio_unregister_device().
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free memory corruption
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel’s UIO subsystem, a device becomes visible to userspace after device_add() but before the registration process completes. If a later initialization step fails, the unwind logic removes the device yet leaves idev->info pointing to a caller‑owned struct uio_info. An orphaned open file descriptor that holds a reference to the uio_device can race with the failure path; when the caller frees uio_info, subsequent file operations dereference the now‑dangling pointer, producing a use‑after‑free bug that can corrupt kernel memory; based on the description, it is inferred that this could allow arbitrary code execution, though the description does not state this conclusively.

Affected Systems

All Linux kernel versions that do not yet incorporate the commit which clears the stale uio_info pointer are affected. This includes every distribution kernel lacking the patch and any custom UIO driver that registers a device via device_add and fails during initialization without performing the proper cleanup.

Risk and Exploitability

The CVSS score of 7.0 indicates moderate to high severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require the ability to register a UIO device and to coordinate a race between opening /dev/uioX and the failure cleanup. This capability typically implies local privileged access to load a kernel module or similar privilege; this inference is noted because the description does not explicitly state the attacker model.

Generated by OpenCVE AI on September 20, 2026 at 01:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch or upgrade to a kernel release that includes the commit which clears the stale uio_info pointer before freeing the structure.
  • Restrict access to /dev/uio* devices to privileged users or disable the UIO subsystem when it is not required.
  • Ensure that on driver registration failure the driver removes UIO attributes, clears the uio_info pointer within a protected lock, and notifies existing open processes to avoid dangling references.

Generated by OpenCVE AI on September 20, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration path After device_add(), the UIO device is visible to userspace and /dev/uioX can be opened. If a later setup step fails, __uio_register_device() unwinds the device but leaves idev->info pointing at the caller-owned struct uio_info. That is unsafe when an opener races with the failed registration path. The open file keeps a reference to the uio_device, while the caller sees registration failure and may free its struct uio_info. Later file operations can then follow idev->info and dereference freed memory. Handle post-device_add() failures like unregister: remove UIO attributes while the info pointer is still valid, then clear idev->info under info_lock and wake existing waiters/async users before removing the device and minor. This makes already-open file descriptors observe the same "device gone" state as normal uio_unregister_device().
Title uio: Fix stale info pointer in failed registration path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:48.391Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.923

Modified: 2026-09-18T18:18:19.403

Link: CVE-2026-93054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses