{"id":"CVE-2026-53161","summary":"misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: fix use-after-free of fastrpc_user in workqueue context\n\nThere is a race between fastrpc_device_release() and the workqueue\nthat processes DSP responses. When the user closes the file descriptor,\nfastrpc_device_release() frees the fastrpc_user structure. Concurrently,\nan in-flight DSP invocation can complete and fastrpc_rpmsg_callback()\nschedules context cleanup via schedule_work(&ctx-\u003eput_work). If the\nworkqueue runs fastrpc_context_free() in parallel with or after\nfastrpc_device_release() has freed the user structure, it dereferences\nthe freed fastrpc_user. Depending on the state of the context at the\ntime of the race, any one of the following accesses can be hit:\n\n 1. fastrpc_buf_free() calls fastrpc_ipa_to_dma_addr(buf-\u003efl-\u003ecctx, ...)\n    to strip the SID bits from the stored IOVA before passing the\n    physical address to dma_free_coherent().\n\n 2. fastrpc_free_map() reads map-\u003efl-\u003ecctx-\u003evmperms[0].vmid to\n    reconstruct the source permission bitmask needed for the\n    qcom_scm_assign_mem() call that returns memory from the DSP VM\n    back to HLOS.\n\n 3. fastrpc_free_map() acquires map-\u003efl-\u003elock to safely remove the\n    map node from the fl-\u003emaps list.\n\nThe resulting use-after-free manifests as:\n\n  pc : fastrpc_buf_free+0x38/0x80 [fastrpc]\n  lr : fastrpc_context_free+0xa8/0x1b0 [fastrpc]\n  fastrpc_context_free+0xa8/0x1b0 [fastrpc]\n  fastrpc_context_put_wq+0x78/0xa0 [fastrpc]\n  process_one_work+0x180/0x450\n  worker_thread+0x26c/0x388\n\nAdd kref-based reference counting to fastrpc_user. Have each invoke\ncontext take a reference on the user at allocation time and release it\nwhen the context is freed. Release the initial reference in\nfastrpc_device_release() at file close. Move the teardown of the user\nstructure — freeing pending contexts, maps, mmaps, and the channel\ncontext reference — into the kref release callback fastrpc_user_free(),\nso that it runs only when the last reference is dropped, regardless of\nwhether that happens at device close or after the final in-flight\ncontext completes.","modified":"2026-07-21T10:00:03.575784007Z","published":"2026-06-25T08:38:42.789Z","related":["CGA-592r-q97c-mjqf","SUSE-SU-2026:3130-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53161.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/5278ccd357e0d7aeeb1e76c0f3e0e02894a9897c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c6e5c2be09f814377d7f1ce97370a5b7b3e02814"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d42679eef34dd590b694ce3b666c5e2ba10cd4bf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/df08fadcf0e5f3708365ec3b6d30b5aafd98bea1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e1e3a05efe5954d5bad01157d79429d39a67a7ae"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e85eb5feca8e254905ffa6c57a3c99c89a674a0f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecea4967c2bff92c2fafbc59893f711b39f7b152"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fbe0947420eec18a84638d29468c2d563ce4e6a3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53161.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53161"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6cffd79504ce040f460831030d3069fa1c99bb71"},{"fixed":"c6e5c2be09f814377d7f1ce97370a5b7b3e02814"},{"fixed":"e1e3a05efe5954d5bad01157d79429d39a67a7ae"},{"fixed":"d42679eef34dd590b694ce3b666c5e2ba10cd4bf"},{"fixed":"df08fadcf0e5f3708365ec3b6d30b5aafd98bea1"},{"fixed":"ecea4967c2bff92c2fafbc59893f711b39f7b152"},{"fixed":"5278ccd357e0d7aeeb1e76c0f3e0e02894a9897c"},{"fixed":"fbe0947420eec18a84638d29468c2d563ce4e6a3"},{"fixed":"e85eb5feca8e254905ffa6c57a3c99c89a674a0f"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53161.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.94"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.36"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.13"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53161.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}