CVE-2026-53161 PUBLISHED

misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context

Assigner: Linux
Reserved: 09.06.2026 Published: 25.06.2026 Updated: 25.06.2026

In the Linux kernel, the following vulnerability has been resolved:

misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context

There is a race between fastrpc_device_release() and the workqueue that processes DSP responses. When the user closes the file descriptor, fastrpc_device_release() frees the fastrpc_user structure. Concurrently, an in-flight DSP invocation can complete and fastrpc_rpmsg_callback() schedules context cleanup via schedule_work(&ctx->put_work). If the workqueue runs fastrpc_context_free() in parallel with or after fastrpc_device_release() has freed the user structure, it dereferences the freed fastrpc_user. Depending on the state of the context at the time of the race, any one of the following accesses can be hit:

  1. fastrpc_buf_free() calls fastrpc_ipa_to_dma_addr(buf->fl->cctx, ...) to strip the SID bits from the stored IOVA before passing the physical address to dma_free_coherent().

  2. fastrpc_free_map() reads map->fl->cctx->vmperms[0].vmid to reconstruct the source permission bitmask needed for the qcom_scm_assign_mem() call that returns memory from the DSP VM back to HLOS.

  3. fastrpc_free_map() acquires map->fl->lock to safely remove the map node from the fl->maps list.

The resulting use-after-free manifests as:

pc : fastrpc_buf_free+0x38/0x80 [fastrpc] lr : fastrpc_context_free+0xa8/0x1b0 [fastrpc] fastrpc_context_free+0xa8/0x1b0 [fastrpc] fastrpc_context_put_wq+0x78/0xa0 [fastrpc] process_one_work+0x180/0x450 worker_thread+0x26c/0x388

Add kref-based reference counting to fastrpc_user. Have each invoke context take a reference on the user at allocation time and release it when the context is freed. Release the initial reference in fastrpc_device_release() at file close. Move the teardown of the user structure — freeing pending contexts, maps, mmaps, and the channel context reference — into the kref release callback fastrpc_user_free(), so that it runs only when the last reference is dropped, regardless of whether that happens at device close or after the final in-flight context completes.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to c6e5c2be09f814377d7f1ce97370a5b7b3e02814 (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to e1e3a05efe5954d5bad01157d79429d39a67a7ae (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to d42679eef34dd590b694ce3b666c5e2ba10cd4bf (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to df08fadcf0e5f3708365ec3b6d30b5aafd98bea1 (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to ecea4967c2bff92c2fafbc59893f711b39f7b152 (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to 5278ccd357e0d7aeeb1e76c0f3e0e02894a9897c (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to fbe0947420eec18a84638d29468c2d563ce4e6a3 (excl.)
  • affected from 6cffd79504ce040f460831030d3069fa1c99bb71 to e85eb5feca8e254905ffa6c57a3c99c89a674a0f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.1 is affected
  • unaffected from 0 to 5.1 (excl.)
  • unaffected from 5.10.259 to 5.10.* (incl.)
  • unaffected from 5.15.210 to 5.15.* (incl.)
  • unaffected from 6.1.176 to 6.1.* (incl.)
  • unaffected from 6.6.143 to 6.6.* (incl.)
  • unaffected from 6.12.94 to 6.12.* (incl.)
  • unaffected from 6.18.36 to 6.18.* (incl.)
  • unaffected from 7.0.13 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References