CVE-2026-80923
Reported by Linux · Published September 9, 2026
In the Linux kernel, the following vulnerability has been resolved: xhci: dbgtty: Fix unregister on tty_register_driver() failure If tty_register_driver() fails, it drops the reference, but fails to set the global dbc_tty_driver to NULL, causing the unregister to be called again when module exits. On module unload dbc_tty_exit() only gates its cleanup on the driver pointer being non-NULL, so it operates on the already-freed driver: module_init(xhci_hcd_init) xhci_hcd_init() xhci_dbc_init() [return value ignored] dbc_tty_init() tty_register_driver() fails tty_driver_kref_put() -> driver freed (dbc_tty_driver left dangling) ... module_exit(xhci_hcd_fini) xhci_hcd_fini() xhci_dbc_exit() dbc_tty_exit() if (dbc_tty_driver) -> true (dangling) tty_unregister_driver() -> use-after-free
EPSS 0.16% · 6.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 4521f16139409cdf9462c7325d43454462cff6c3, 4521f16139409cdf9462c7325d43454462cff6c3, 4521f16139409cdf9462c7325d43454462cff6c3 |
| Linux | Linux | 5.9, 0, 5.15.220 |
| linux | linux_kernel | 5.9, 5.9, 5.9 |
| Linux | Linux | 4521f16139409cdf9462c7325d43454462cff6c3, 4521f16139409cdf9462c7325d43454462cff6c3, 4521f16139409cdf9462c7325d43454462cff6c3 |
Timeline
- Sep 9, 2026 Coalition ESS Score
- Sep 9, 2026 CVE Published
- Sep 10, 2026 EPSS Score
- Sep 17, 2026 EPSS Score