CVE-2026-93050EPSS p9.6%
CVE-2026-93050CVE-2026-93050
Description
In the Linux kernel, the following vulnerability has been resolved:
ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
Three issues arise when the device is removed while a tty session is
still active:
1. UAF of struct ipoctal: the remove callback frees ipoctal via
kfree() while tty ops may still access it. Fix by introducing
kref-based lifetime management — kref is taken in install() when
a tty is opened and released in cleanup() when the tty is finally
destroyed; remove() uses kref_put() instead of kfree().
2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove()
frees xmit_buf via tty_port_free_xmit_buf() while a userspace
process may still hold the tty fd and call write(). Fix by
checking for NULL xmit_buf in ipoctal_write_tty().
3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)
dereferences ipoctal->dev after the ipack_device has been freed
by ipack_device_del(). Fix by caching ipoctal->carrier_owner
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |