PT-2026-65218 · Linux · Linux
CVE-2026-64543
·
Published
2026-07-27
·
Updated
2026-07-27
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix use-after-free of the discoverer in tipc disc rcv()
bearer disable() frees b->disc with tipc disc delete()'s plain kfree(),
but tipc disc rcv() still dereferences b->disc in RX softirq under
rcu read lock() (tipc udp recv -> tipc rcv -> tipc disc rcv).
L2 bearers are safe thanks to the synchronize net() in
tipc disable l2 media(), but the UDP bearer defers that call to the
cleanup bearer() workqueue, so the discoverer is freed with no grace
period:
BUG: KASAN: slab-use-after-free in tipc disc rcv (net/tipc/discover.c:149)
Read of size 8 at addr ffff88802348b728 by task poc tipc/184
tipc disc rcv (net/tipc/discover.c:149)
tipc rcv (net/tipc/node.c:2126)
tipc udp recv (net/tipc/udp media.c:391)
udp rcv (net/ipv4/udp.c:2643)
ip local deliver finish (net/ipv4/ip input.c:241)
Freed by task 181:
kfree (mm/slub.c:6565)
bearer disable (net/tipc/bearer.c:418)
tipc nl bearer disable (net/tipc/bearer.c:1001)
The bearer is freed with kfree rcu(); free the discoverer the same way.
Add an rcu head to struct tipc discoverer and free it and its skb from an
RCU callback.
Because the RCU callback (tipc disc free rcu) lives in module text, a
call rcu() that is still pending when the tipc module is unloaded would
invoke a freed function. Add an rcu barrier() to tipc exit() after the
bearer subsystem has been torn down, so all pending discoverer callbacks
have run before the module text goes away.
Reachable from an unprivileged user namespace: the TIPCv2 genl family is
netnsok and its bearer commands have no GENL ADMIN PERM. Needs CONFIG TIPC
and CONFIG TIPC MEDIA UDP.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux