CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel, specifically in the driver core where the function dev_has_sync_state() reads the dev->driver variable without proper locking, potentially leading to a race condition during device unbinding. This could result in undefined behavior or crashes due to dereferencing a stale pointer. Linux system administrators and developers should prioritize this issue to ensure the stability and security of their systems, particularly those managing device drivers.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() dev_has_sync_state() reads dev->driver twice without holding device_lock() -- once for the NULL check and once to dereference ->sync_state. Some callers only hold device_links_write_lock, which doesn't prevent a concurrent unbind from clearing dev->driver via device_unbind_cleanup(). Fix it by reading dev->driver exactly once with READ_ONCE(), pairing with the WRITE_ONCE() in device_set_driver().