From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CBDD43E9C3 for ; Fri, 4 Sep 2026 15:58:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537490; cv=none; b=kxHihOUY3O+locVA4df+L/PWGieDIiwac6TiiY7qS2nRp5sXVbbA7iqTaYRrU/B54vOkDOK6o4IsPYFI5pFfzYIeGKtDpTyTjGEMr2QbSFNARV3B84JT7emgoSBkttR68tndHsc6IGYW2eUv7jRGq11L1nn3Fa0tinzOBiJvaCU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537490; c=relaxed/simple; bh=CSwli/h/dJS2B7xVjytPk3P+RWCDYg5e4o+CA1h+f4Q=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=c1CwRnFS0cS7dd7fOhhLq9zcxbJAN61BclNNJJfT/r22+EUZ/Cn9/6InmRl/CeiLmva+e5KTWS/BkXY2bJusmidRO0i/YvEeqASCq5PflUmdftDcVytIDOUdlajhNFo/0GQ3f4nmUdUjDpDyHo6D4fe3ydLrXFEHp7sLGA+PihY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=m6cJVj0D; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="m6cJVj0D" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5B7A51F00A3F; Fri, 4 Sep 2026 15:58:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788537489; bh=L1Y5QgTXWlIyYOD9RQMr63TOIH9eY3+5neEyuc73tWo=; h=From:To:Cc:Subject:Date:Reply-To; b=m6cJVj0DkZmnIblBlOrCqu5bW6MAg8B28sMakHBidyOvYIERj/E51dVhVHjwc3PMB xtUIay1HlrrG5vzDwYoPCfIglNkws/PBRg2N//0BIpDcolc0kApsrKeAo2FfAETH0y 8bwhqT5XIxlfCQ1jqhm/C+bQemg7gbKJPy6lW6a8= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80854: usb: gadget: f_tcm: keep port count until LUN teardown completes Date: Fri, 4 Sep 2026 17:53:21 +0200 Message-ID: <2026090401-CVE-2026-80854-30d6@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4500; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=KRxkL7fBA/Hylz1fZ3yryH42rmK8FixzdienxlxvYCk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzXsaKOxjuYjKWuxbvtjD+yCc/g+LVq3bcWCRWN+m/o 2HeyhLRjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZiI7n2G+U6FCT+fyH7b67FJ R2L2C68VT/uaFzDMsw+/vn+a+s9V2tVaSvxTH2jtDX18BQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from the fabric_pre_unlink() callback, before core_dev_del_lun() waits for active se_lun references to drain. If removal of the last LUN races a nexus removal, the latter can observe a zero port count and call target_remove_session(). This frees sess_cmd_map while an in-flight struct usbg_cmd, including its work item, can still be accessed. Overlapping the last-LUN unlink with nexus removal reproduces this lifetime violation as a DEBUG_OBJECTS "free active" warning for usbg_cmd_work, followed by a target-core BUG/Oops. The generic target-core unlink path has no callback after core_dev_del_lun() completes. Add an optional fabric_post_unlink() callback and use it for the f_tcm port count. The count now remains nonzero until core_dev_del_lun() has finished draining active LUN references, preventing nexus removal from freeing the session during command completion. The Linux kernel CVE team has assigned CVE-2026-80854 to this issue. Affected and fixed versions =========================== Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 5.10.269 with commit c494c5562ca69b61a82f566e3b87a445d2c28929 Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 5.15.220 with commit c1f359d9a5efed458946063de65ddbeaacc4f165 Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.1.187 with commit 178f59a0bccd3f66cdfa5184310f31a58b7257c4 Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.6.156 with commit ad6f0375d2e93a1d8c015463e5e92dfcb26e311b Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.12.108 with commit 2efbfd42441d3ef8137aff2d59e9835e1d5ae780 Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.18.49 with commit 85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95 Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 7.1.13 with commit bbd6aa311a9f4dd17822c7557451458d3d2e980b Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 7.2.3 with commit eaa96a8458f54d6cf0954242ab8b1df2a6fccafa Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 7.3-rc1 with commit c39d0916da47d94909391876c9e5bd429ea7b1b9 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80854 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/target/target_core_fabric_configfs.c drivers/usb/gadget/function/f_tcm.c include/target/target_core_fabric.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929 https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165 https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4 https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780 https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95 https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9