{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89942","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.777Z","datePublished":"2026-09-16T10:32:29.836Z","dateUpdated":"2026-09-16T14:40:29.770Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:40:29.770Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: buffer: Fix potential use-after-free in anonymous buffer release\n\nAn anonymous buffer handle holds a reference to the underlying IIO device.\nThe reference is dropped in the buffer handle's release function. If the\ndevice has been removed, either through unbind or hot-unplug, the buffer\nhandle might hold the last reference.\n\nThe release function takes the mutex for the buffer using a guard, which\nmeans the unlock happens after all the code in the function, including\n`iio_device_put()`. If the anonymous buffer holds the last reference this\nmight free both the IIO device and the buffer, which contains the mutex,\nleading to use-after-free when the mutex is unlocked.\n\nFix this by using a scoped guard just around the buffer dmabuf list access,\nmaking sure the mutex is unlocked before releasing the IIO device.\n\nVersion 10 of the patch that introduced this issue used this exact scheme\nof first unlocking and then dropping the reference [1]. During review it\nwas suggested to use a guard instead, and version 11 made that change [2]."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker reaches the bug by opening /dev/iio:deviceX, issuing IIO_BUFFER_GET_FD_IOCTL to get an anonymous IIO buffer fd, then closing that fd after the IIO device is gone. That is a local char-device ioctl/close path, not a network or USB descriptor parser.\nAC:L - This is a deterministic lifetime UAF, not a race: close() on the buffer fd unlocks buffer->dmabufs_mutex after iio_device_put() has already freed it. The attacker controls open/ioctl/close and can drop the last device reference by hot-unplugging a USB IIO or HID-sensor device they opened.\nPR:L - iio_chrdev_open() and IIO_BUFFER_GET_FD_IOCTL perform no capability checks; access is only by /dev/iio:deviceX file mode. An unprivileged local user who can open that node (iio group, industrial DAQ, sensor HAL) can obtain the anonymous buffer fd.\nUI:N - The attacker opens the IIO device, obtains the buffer fd, removes the device, and closes the fd themselves. No separate victim action is required.\nS:U - The use-after-free is in kernel IIO buffer teardown and can escalate privileges only within the same kernel/OS authority. It does not cross a VM, IOMMU, or other security boundary.\nC:H - Closing the anonymous buffer fd use-after-frees the IIO buffer object that embeds dmabufs_mutex. A kernel heap UAF can be reclaimed to build an arbitrary read primitive.\nI:H - The cleanup guard unlocks dmabufs_mutex after iio_dev_release() has already destroyed that mutex and freed the buffer, writing into freed kernel memory. That UAF is exploitable for heap corruption and control-flow hijack.\nA:H - Use-after-free of the buffer mutex during anonymous-buffer release can oops or panic the kernel even without a fully controlled exploit, causing complete availability loss."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iio/industrialio-buffer.c"],"versions":[{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"ab53077511cde811bf3ee219426c522329c41226","status":"affected","versionType":"git"},{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"f1f8f0e8e0af9cae8150658dc7bb51332f984893","status":"affected","versionType":"git"},{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"6d4bdbf7bad63e759bf20259c527f69a1209e3dd","status":"affected","versionType":"git"},{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"6288b593e76eb10329326f2cd51e32557203b9e5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iio/industrialio-buffer.c"],"versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ab53077511cde811bf3ee219426c522329c41226"},{"url":"https://git.kernel.org/stable/c/f1f8f0e8e0af9cae8150658dc7bb51332f984893"},{"url":"https://git.kernel.org/stable/c/6d4bdbf7bad63e759bf20259c527f69a1209e3dd"},{"url":"https://git.kernel.org/stable/c/6288b593e76eb10329326f2cd51e32557203b9e5"}],"title":"iio: buffer: Fix potential use-after-free in anonymous buffer release","x_generator":{"engine":"bippy-1.2.0"}}}}