{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53024","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.379Z","datePublished":"2026-06-24T16:29:33.184Z","dateUpdated":"2026-08-05T12:32:41.861Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:32:41.861Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: raw: fix use-after-free if write is called after disconnect\n\nIf a user writes to the chardev after disconnect has been called, the\nkernel panics with the following trace (with\nCONFIG_INIT_ON_FREE_DEFAULT_ON=y):\n\n        BUG: kernel NULL pointer dereference, address: 0000000000000218\n         ...\n        Call Trace:\n         <TASK>\n         gb_operation_create_common+0x61/0x180\n         gb_operation_create_flags+0x28/0xa0\n         gb_operation_sync_timeout+0x6f/0x100\n         raw_write+0x7b/0xc7 [gb_raw]\n         vfs_write+0xcf/0x420\n         ? task_mm_cid_work+0x136/0x220\n         ksys_write+0x63/0xe0\n         do_syscall_64+0xa4/0x290\n         entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nDisconnect calls gb_connection_destroy, which ends up freeing the\nconnection object. When gb_operation_sync is called in the write file\noperations, its gets a freed connection as parameter and the kernel\npanics.\n\nThe gb_connection_destroy cannot be moved out of the disconnect\nfunction, as the Greybus subsystem expect all connections belonging to a\nbundle to be destroyed when disconnect returns.\n\nTo prevent this bug, use a rw lock to synchronize access between write\nand disconnect. This guarantees that the write function doesn't try\nto use a disconnected connection."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable path is reached by a local `write(2)` to the Greybus raw character device, not by network packets. Although disconnect can be caused by Greybus hotplug/removal events, the crashing UAF is triggered from the local file operation.\nAC:L - After a process keeps the raw chardev open across disconnect, a subsequent write reliably uses the destroyed `gb_connection`; no hard race or attacker-uncontrolled memory layout is required to trigger the bug. Under the conservative rule, the UAF exploitation complexity is Low.\nPR:L - The raw driver has no capability, ioctl, or authentication checks in open/write; access is gated by ordinary permission to the created chardev. A basic local user with write access to that device can reach the vulnerable path.\nUI:N - The attacker can open the device, keep the fd, and issue the write after disconnect without requiring another user to perform an action. No victim interaction is inherent to the vulnerable syscall path.\nS:U - The impact is within the kernel/host security authority. This is not a guest-to-host, IOMMU, or separate-scope boundary crossing.\nC:H - The bug is a use-after-free of `struct gb_connection`, and the stale object is dereferenced by Greybus operation creation and transport paths. As a kernel UAF, it is conservatively treated as capable of enabling kernel memory disclosure.\nI:H - The freed connection contains pointers used to reach host-device and driver operation paths, so heap reuse could plausibly turn the stale pointer into control-flow or write primitives. Under the required conservative UAF guidance, integrity impact is High.\nA:H - The upstream report shows a kernel panic/NULL dereference when writing after disconnect, and UAFs can repeatedly crash the kernel. Availability impact is therefore High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/greybus/raw.c"],"versions":[{"version":"e806c7fb8e9bae87fc23958c3789f2c2f96f54a4","lessThan":"48d6c32bc049abd114e8f0836c0e7d7cbfba7827","status":"affected","versionType":"git"},{"version":"e806c7fb8e9bae87fc23958c3789f2c2f96f54a4","lessThan":"84265cbd96b97058ef67e3f8be3933667a000835","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/greybus/raw.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/48d6c32bc049abd114e8f0836c0e7d7cbfba7827"},{"url":"https://git.kernel.org/stable/c/84265cbd96b97058ef67e3f8be3933667a000835"}],"title":"greybus: raw: fix use-after-free if write is called after disconnect","x_generator":{"engine":"bippy-1.2.0"}}}}