{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80677","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.783Z","datePublished":"2026-08-28T06:49:15.507Z","dateUpdated":"2026-08-29T06:22:03.959Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:22:03.959Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: use READ_ONCE() for dev->driver in dev_has_sync_state()\n\ndev_has_sync_state() reads dev->driver twice without holding\ndevice_lock() -- once for the NULL check and once to dereference\n->sync_state. Some callers only hold device_links_write_lock, which\ndoesn't prevent a concurrent unbind from clearing dev->driver via\ndevice_unbind_cleanup().\n\nFix it by reading dev->driver exactly once with READ_ONCE(), pairing\nwith the WRITE_ONCE() in device_set_driver()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is in the driver-core device-link sync_state path, reached only via local device lifecycle operations (probe/bind, sysfs unbind, USBDEVFS disconnect/connect, module unload); there is no network, Bluetooth, or remote protocol entry point into dev_has_sync_state().\nAC:L - An attacker controls both race sides: one thread drives device_links_driver_bound() through USB connect/probe or bind while another hammers USBDEVFS_DISCONNECT or sysfs unbind on the same or linked supplier device, retriable at high frequency with no outcome depending on uncontrollable victim state.\nPR:L - USBDEVFS_DISCONNECT and USBDEVFS_CONNECT on /dev/bus/usb require no capability checks—only rw access to the usbfs node that udev uaccess rules routinely grant seat users—so unprivileged local users can drive the supplier unbind concurrent with automatic probe/link updates without init-namespace root.\nUI:N - The attacker initiates both the probe/device-link update and the concurrent unbind from their own processes; USB hotplug and automatic driver binding on shared workstations or kiosks also exercise this path without any deliberate action by another user.\nS:U - The TOCTOU and any resulting kernel memory fault or corruption stay within the host kernel driver-core security authority; exploitation does not cross VM, IOMMU, or sandbox boundaries.\nC:H - Between the two unsynchronized dev->driver loads, concurrent device_unbind_cleanup() can clear the pointer (NULL dereference of ->sync_state) or leave a stale device_driver pointer whose sync_state field is read from freed module memory—a use-after-free read per kernel CNA UAF guidance.\nI:H - Use-after-free and torn pointer reads of dev->driver grant attacker-influenced heap reuse over the device_driver object; per CNA guidance UAF races enable corruption primitives and the freed sync_state function-pointer field can steer subsequent sync_state() dispatch on linked devices.\nA:H - Reloading dev->driver as NULL between the two reads makes dev->driver->sync_state a NULL-page dereference, and the stale-pointer or post-rmmod variant faults on unmapped memory—either way a repeatable kernel oops/panic in driver-core device-link processing."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/device.h"],"versions":[{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"89789e4c141904506163dcb91c7289a074573931","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"51b3e1de53ee5b7775c7ff90e67fdb2665fce938","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"358697929351f619143f59c6a8a15a4994748b79","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"5e79e0180515b31b2e2244dc3d256fd8b5a07021","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"860885fcd2611bca8c28dac8b2c1c7ff160f763e","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"cc77f0d91e3214e4292208f02a1dc09a31f9aac7","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"9b0f4082a09760939588135d60a8e9cc994bfa3e","status":"affected","versionType":"git"},{"version":"ac338acf514e7b578fa9e3742ec2c292323b4c1a","lessThan":"e9506871a8ea304cde48ff4a57226df2aadddae3","status":"affected","versionType":"git"},{"version":"6d88283a49425eb469aa60ffebe76539e73c933e","status":"affected","versionType":"git"},{"version":"5.5.13","lessThan":"5.6","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/device.h"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.13"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/89789e4c141904506163dcb91c7289a074573931"},{"url":"https://git.kernel.org/stable/c/51b3e1de53ee5b7775c7ff90e67fdb2665fce938"},{"url":"https://git.kernel.org/stable/c/358697929351f619143f59c6a8a15a4994748b79"},{"url":"https://git.kernel.org/stable/c/5e79e0180515b31b2e2244dc3d256fd8b5a07021"},{"url":"https://git.kernel.org/stable/c/860885fcd2611bca8c28dac8b2c1c7ff160f763e"},{"url":"https://git.kernel.org/stable/c/cc77f0d91e3214e4292208f02a1dc09a31f9aac7"},{"url":"https://git.kernel.org/stable/c/9b0f4082a09760939588135d60a8e9cc994bfa3e"},{"url":"https://git.kernel.org/stable/c/e9506871a8ea304cde48ff4a57226df2aadddae3"}],"title":"driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()","x_generator":{"engine":"bippy-1.2.0"}}}}