PT-2026-65218 · Linux · Linux

CVE-2026-64543

·

Published

2026-07-27

·

Updated

2026-07-27

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix use-after-free of the discoverer in tipc disc rcv()
bearer disable() frees b->disc with tipc disc delete()'s plain kfree(), but tipc disc rcv() still dereferences b->disc in RX softirq under rcu read lock() (tipc udp recv -> tipc rcv -> tipc disc rcv).
L2 bearers are safe thanks to the synchronize net() in tipc disable l2 media(), but the UDP bearer defers that call to the cleanup bearer() workqueue, so the discoverer is freed with no grace period:
BUG: KASAN: slab-use-after-free in tipc disc rcv (net/tipc/discover.c:149) Read of size 8 at addr ffff88802348b728 by task poc tipc/184 tipc disc rcv (net/tipc/discover.c:149) tipc rcv (net/tipc/node.c:2126) tipc udp recv (net/tipc/udp media.c:391) udp rcv (net/ipv4/udp.c:2643) ip local deliver finish (net/ipv4/ip input.c:241) Freed by task 181: kfree (mm/slub.c:6565) bearer disable (net/tipc/bearer.c:418) tipc nl bearer disable (net/tipc/bearer.c:1001)
The bearer is freed with kfree rcu(); free the discoverer the same way. Add an rcu head to struct tipc discoverer and free it and its skb from an RCU callback.
Because the RCU callback (tipc disc free rcu) lives in module text, a call rcu() that is still pending when the tipc module is unloaded would invoke a freed function. Add an rcu barrier() to tipc exit() after the bearer subsystem has been torn down, so all pending discoverer callbacks have run before the module text goes away.
Reachable from an unprivileged user namespace: the TIPCv2 genl family is netnsok and its bearer commands have no GENL ADMIN PERM. Needs CONFIG TIPC and CONFIG TIPC MEDIA UDP.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64543

Affected Products

Linux