In the Linux kernel, the following vulnerability has been resolved:
usbip: vudc: Fix use after free bug in vudc_remove due to race condition
This patch follows up Zheng Wang's 2023 report of a use-after-free in vudc_remove(). The original thread stalled on Shuah Khan's request for runtime testing of the unplug/unbind path. This patch supplies that testing and keeps Zheng's original fix shape.
In vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer(). usbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer(). vudc_remove() can then free the containing struct vudc while the timer is still pending or executing.
KASAN confirms the race on an unpatched x86_64 QEMU guest with CONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop that repeatedly writes a socket fd to usbip_sockfd, closes the socket pair, and unbinds/rebinds usbip-vudc.0:
BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0 Write of size 8 at addr ffff888001b80740 by task trigger_and_unb/239 Allocated by task 239: vudc_probe+0x4d/0xaa0 Freed by task 239: kfree+0x18f/0x520 device_release_driver_internal+0x388/0x540 unbind_store+0xd9/0x100
This lands in the timer core rather than v_timer() itself because the embedded timer_list is being walked after its containing struct vudc has already been freed. The underlying lifetime bug is the same one Zheng reported.
With v_stop_timer() called from vudc_remove() and the timer deleted synchronously, the same harness completed 5000 bind/unbind iterations with no KASAN report.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 20, 2026 | Jul 20, 2026 |
| Ubuntu | — | Upgrade linux-image-oracle-7.0Upgrade linux-image-nvidia-bos-64kUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-aws-64kUpgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-azureUpgrade linux-image-gcpUpgrade linux-image-ibmUpgrade linux-image-oracle-64kUpgrade linux-image-raspiUpgrade linux-image-ibm-7.0Upgrade linux-image-gcp-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-7.0.0-1010-azureUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-nvidiaUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-aws-64k-7.0Upgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-aws-7.0Upgrade linux-image-raspi-realtimeUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-azure-fde-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-raspi-7.0Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-oracleUpgrade linux-image-azure-7.0Upgrade linux-image-nvidia-bosUpgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-nvidia-7.0Upgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-gcp-7.0Upgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-awsUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-7.0.0-1011-gcp-64k | Jul 21, 2026 | Jul 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 27, 2026 | Jul 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub