PT-2026-61378 · Linux · Linux
CVE-2026-64061
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix early put of sink folio in netfs read gaps()
Fix netfs read gaps() to release the sink page it uses after waiting for
the request to complete. The way the sink page is used is that an
ITER BVEC-class iterator is created that has the gaps from the target folio
at either end, but has the sink page tiled over the middle so that a single
read op can fill in both gaps.
The bug was found by KASAN detecting a UAF on the generic/075 xfstest in
the cifsd kernel thread that handles reception of data from the TCP socket:
BUG: KASAN: use-after-free in copy to iter+0x48a/0xa20
Write of size 885 at addr ffff888107f92000 by task cifsd/1285
CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy)
Call Trace:
dump stack lvl+0x5d/0x80
print report+0x17f/0x4f1
kasan report+0x100/0x1e0
kasan check range+0x10f/0x1e0
asan memcpy+0x3c/0x60
copy to iter+0x48a/0xa20
skb datagram iter+0x2c9/0x430
skb copy datagram iter+0x6e/0x160
tcp recvmsg locked+0xce0/0x1130
tcp recvmsg+0xeb/0x300
inet recvmsg+0xcf/0x3a0
sock recvmsg+0xea/0x100
cifs readv from socket+0x3a6/0x4d0 [cifs]
cifs read iter from socket+0xdd/0x130 [cifs]
cifs readv receive+0xaad/0xb10 [cifs]
cifs demultiplex thread+0x1148/0x1740 [cifs]
kthread+0x1cf/0x210
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux