Home

Description

In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_show() The driver_override_show() function reads the driver_override string without holding the device_lock. However, driver_override_store() uses driver_set_override(), which modifies and frees the string while holding the device_lock. This can result in a concurrent use-after-free if the string is freed by the store function while being read by the show function. Fix this by holding the device_lock around the read operation.

PUBLISHED Reserved 2026-01-13 | Published 2026-02-18 | Updated 2026-02-23 | Assigner Linux

Product status

Default status
unaffected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before c71dfb7833db7af652ee8f65011f14c97c47405d
affected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before c424e72cfa67e7e1477035058a8a659f2c0ea637
affected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before b1983840287303e0dfb401b1b6cecc5ea7471e90
affected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before dd8ba8c0c3f3916d4ee1e3a09da9cd5caff5d227
affected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before 1d6bd6183e723a7b256ff34bbb5b498b5f4f2ec0
affected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before a2ae33e1c6361e960a4d00f7cf75d880b54f9528
affected

1f86a00c1159fd77e66b1bd6ff1a183f4d46f34d (git) before 148891e95014b5dc5878acefa57f1940c281c431
affected

Default status
affected

5.10
affected

Any version before 5.10
unaffected

5.15.201 (semver)
unaffected

6.1.164 (semver)
unaffected

6.6.127 (semver)
unaffected

6.12.74 (semver)
unaffected

6.18.11 (semver)
unaffected

6.19.1 (semver)
unaffected

7.0-rc1 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/c71dfb7833db7af652ee8f65011f14c97c47405d

git.kernel.org/...c/c424e72cfa67e7e1477035058a8a659f2c0ea637

git.kernel.org/...c/b1983840287303e0dfb401b1b6cecc5ea7471e90

git.kernel.org/...c/dd8ba8c0c3f3916d4ee1e3a09da9cd5caff5d227

git.kernel.org/...c/1d6bd6183e723a7b256ff34bbb5b498b5f4f2ec0

git.kernel.org/...c/a2ae33e1c6361e960a4d00f7cf75d880b54f9528

git.kernel.org/...c/148891e95014b5dc5878acefa57f1940c281c431

cve.org (CVE-2026-23221)

nvd.nist.gov (CVE-2026-23221)

Download JSON