All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80854: usb: gadget: f_tcm: keep port count until LUN teardown completes
@ 2026-09-04 15:53 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:53 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_tcm: keep port count until LUN teardown completes

tcm_usbg_drop_nexus() permits session removal once tpg_port_count
reaches zero. However, usbg_port_unlink() currently decrements that
count from the fabric_pre_unlink() callback, before core_dev_del_lun()
waits for active se_lun references to drain.

If removal of the last LUN races a nexus removal, the latter can observe
a zero port count and call target_remove_session(). This frees
sess_cmd_map while an in-flight struct usbg_cmd, including its work item,
can still be accessed.

Overlapping the last-LUN unlink with nexus removal reproduces this
lifetime violation as a DEBUG_OBJECTS "free active" warning for
usbg_cmd_work, followed by a target-core BUG/Oops.

The generic target-core unlink path has no callback after
core_dev_del_lun() completes. Add an optional fabric_post_unlink()
callback and use it for the f_tcm port count. The count now remains
nonzero until core_dev_del_lun() has finished draining active LUN
references, preventing nexus removal from freeing the session during
command completion.

The Linux kernel CVE team has assigned CVE-2026-80854 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 5.10.269 with commit c494c5562ca69b61a82f566e3b87a445d2c28929
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 5.15.220 with commit c1f359d9a5efed458946063de65ddbeaacc4f165
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.1.187 with commit 178f59a0bccd3f66cdfa5184310f31a58b7257c4
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.6.156 with commit ad6f0375d2e93a1d8c015463e5e92dfcb26e311b
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.12.108 with commit 2efbfd42441d3ef8137aff2d59e9835e1d5ae780
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 6.18.49 with commit 85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 7.1.13 with commit bbd6aa311a9f4dd17822c7557451458d3d2e980b
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 7.2.3 with commit eaa96a8458f54d6cf0954242ab8b1df2a6fccafa
	Issue introduced in 3.5 with commit c52661d60f636d17e26ad834457db333bd1df494 and fixed in 7.3-rc1 with commit c39d0916da47d94909391876c9e5bd429ea7b1b9

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80854
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/target/target_core_fabric_configfs.c
	drivers/usb/gadget/function/f_tcm.c
	include/target/target_core_fabric.h


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929
	https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165
	https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4
	https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b
	https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780
	https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95
	https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b
	https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa
	https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:58 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:53 CVE-2026-80854: usb: gadget: f_tcm: keep port count until LUN teardown completes Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.