Linuxカーネルにおいて、以下の脆弱性が修正されました。usb: phy: isp1301で、非OFデバイス参照の不均衡を修正しました。UDCドライバのデバイス参照リークを修正する最近の変更では、isp1301_get_client()ヘルパーがOFの場合にのみ返されるI2Cデバイスの参照カウントを増加させていました。そのため、非OFの場合に潜在的なuse-after-freeが発生する可能性がありました。呼び出し元が無条件に参照カウントを減少させることができるように、非OFの場合でも参照カウントを増加させるようにしました。返されるI2Cデバイスの使用中にPHYドライバがバインド解除されることを防ぐものは何もなく、これは本質的に競合状態であることに注意してください。
Linux Linux Kernel 5.10.248 以上 5.11 未満
当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。 また、当該ソフトウェアが扱う全ての情報が書き換えられる可能性があります。 さらに、当該ソフトウェアが完全に停止する可能性があります。 そして、この脆弱性を悪用した攻撃の影響は、他のソフトウェアには及びません。
リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
その他(CWE-Other) [NVD評価]
CVE-2025-71145
National Vulnerability Database (NVD) : CVE-2025-71145 関連文書 : usb: phy: isp1301: fix non-OF device reference imbalance - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/43e58abad6c08c5f0943594126ef4cd6559aac0b) 関連文書 : usb: phy: isp1301: fix non-OF device reference imbalance - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906) 関連文書 : usb: phy: isp1301: fix non-OF device reference imbalance - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/5d3df03f70547d4e3fc10ed4381c052eff51b157) 関連文書 : usb: phy: isp1301: fix non-OF device reference imbalance - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/7501ecfe3e5202490c2d13dc7e181203601fcd69) 関連文書 : usb: phy: isp1301: fix non-OF device reference imbalance - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/03bbdaa4da8c6ea0c8431a5011db188a07822c8a) 関連文書 : usb: phy: isp1301: fix non-OF device reference imbalance - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3)
[2026年03月02日] 掲載