In the Linux kernel, the following vulnerability has been resolved:
ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
Three issues arise when the device is removed while a tty session is still active:
- UAF of struct ipoctal: the remove callback frees ipoctal via
- NULL dereference in ipoctal_write_tty(): __ipoctal_remove()
- UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)
Also introduce a "removed" flag in struct ipoctal, set at the start of __ipoctal_remove(), and checked in every tty op that accesses hardware resources (port_activate, write_tty, set_termios, hangup, shutdown). This prevents page faults when devm_ioremap() regions are unmapped after remove() returns.