CVE-2026-80923 PUBLISHED

xhci: dbgtty: Fix unregister on tty_register_driver() failure

Assigner: Linux
Reserved: 26.08.2026 Published: 09.09.2026 Updated: 09.09.2026

In the Linux kernel, the following vulnerability has been resolved:

xhci: dbgtty: Fix unregister on tty_register_driver() failure

If tty_register_driver() fails, it drops the reference, but fails to set the global dbc_tty_driver to NULL, causing the unregister to be called again when module exits.

On module unload dbc_tty_exit() only gates its cleanup on the driver pointer being non-NULL, so it operates on the already-freed driver:

<pre>module_init(xhci_hcd_init) xhci_hcd_init() xhci_dbc_init() [return value ignored] dbc_tty_init() tty_register_driver() fails tty_driver_kref_put() -> driver freed (dbc_tty_driver left dangling) ... module_exit(xhci_hcd_fini) xhci_hcd_fini() xhci_dbc_exit() dbc_tty_exit() if (dbc_tty_driver) -> true (dangling) tty_unregister_driver() -> use-after-free </pre>

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to 01b7bc0938061f2fd46e0094f6483d8c6c02f7d3 (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to 43635ff6401ca0e0ed21875379eeded921321525 (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to eaca2814f32b9872a332326324b9e83e01f156d2 (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to 943f976c93e70563b132f5585ff68b08c89641a2 (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to 0d0faf3cc44c4d86fc6faf5cea972c0fbe00b922 (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to 33ed35ca629477f57e0dd1d77d6df96cf5a9eb55 (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to 0e469b94fbba8eb03666da41dd1082b793c50c1a (excl.)
  • affected from 4521f16139409cdf9462c7325d43454462cff6c3 to a916fa66a43e10f63198b6ce978badffc678821a (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.9 is affected
  • unaffected from 0 to 5.9 (excl.)
  • unaffected from 5.15.220 to 5.15.* (incl.)
  • unaffected from 6.1.187 to 6.1.* (incl.)
  • unaffected from 6.6.156 to 6.6.* (incl.)
  • unaffected from 6.12.108 to 6.12.* (incl.)
  • unaffected from 6.18.49 to 6.18.* (incl.)
  • unaffected from 7.1.13 to 7.1.* (incl.)
  • unaffected from 7.2.3 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References