# CVE-2026-81008

## Summary

- **CVE ID:** CVE-2026-81008
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

interconnect: Fix use after free in icc_get() and of_icc_get_by_index()

In of_icc_get_by_index() and icc_get(), if the dynamic allocation for
path->name fails via kasprintf(), the error handling path directly
calls kfree(path) to free the path object and returns an error.

However, prior to this point, path_find() calls path_init(), which
already links the path's requests into the req_list of the respective
interconnect nodes via hlist_add_head(). Directly invoking kfree(path)
leaves dangling pointers in the hlist. A subsequent call to icc_get()
or icc_set_bw() will traverse or modify these corrupted lists, triggering
a slab use afterfree.

KASAN report showing the vulnerability when reproducing via debugfs:

  BUG: KASAN: slab-use-after-free in path_find+0x6f8/0xcfc
  Write of size 8 at addr fff000000d43f748 by task sh/1
  ...
  Call trace:
   kasan_report+0xac/0xfc
   path_find+0x6f8/0xcfc
   icc_get+0x148/0x380
   icc_get_set+0xf8/0x2d0
  ...
  Freed by task 1:
   kfree+0x1a0/0x4a4
   icc_get+0x2cc/0x380
   icc_get_set+0xf8/0x2d0

Fix this by replacing kfree(path) with the proper teardown function,
icc_put(path), which safely removes the requests from the req_list using
hlist_del() and drops the provider usage references before freeing the
memory.

Additionally, in icc_get(), ensure that the icc_lock mutex is released
prior to calling icc_put(path) to avoid a deadlock, as icc_put()
internally acquires the same lock.

## Affected Products

- Linux — Linux (3791163602f7140011a8dc1691cfe6ec0cb1ef07)
- Linux — Linux (5.6)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/a4e9aa7907ade87d1d96853d14e05dcf682f8363)
- [CNA](https://git.kernel.org/stable/c/db8147c5d5ad2cfa21c2be566f95981b41b05de6)
- [CNA](https://git.kernel.org/stable/c/d715d19cfcfe99f361adb05cefc143a95d400b87)
- [CNA](https://git.kernel.org/stable/c/25c7e242aca084fdc1098248194032317dca625d)
- [CNA](https://git.kernel.org/stable/c/03c3af594dea9196cf6ca70d914b42aa8c873c35)
- [CNA](https://git.kernel.org/stable/c/d4d73decdb9a44a248b1cbd04ed6f334df544d9c)
- [CNA](https://git.kernel.org/stable/c/9a671125d4228357e5b929733c4593d27a273749)
- [CNA](https://git.kernel.org/stable/c/fedea72e8f312fe7d0c6cb19353e61d2d5643b11)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._