CVE-2026-64543
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(), but tipc_disc_rcv() still dereferences b->disc in RX softirq under rcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).
L2 bearers are safe thanks to the synchronize_net() in tipc_disable_l2_media(), but the UDP bearer defers that call to the cleanup_bearer() workqueue, so the discoverer is freed with no grace period:
The bearer is freed with kfree_rcu(); free the discoverer the same way. Add an rcu_head to struct tipc_discoverer and free it and its skb from an RCU callback.
Leer descripción completaMostrar menos
Because the RCU callback (tipc_disc_free_rcu) lives in module text, a call_rcu() that is still pending when the tipc module is unloaded would invoke a freed function. Add an rcu_barrier() to tipc_exit() after the bearer subsystem has been torn down, so all pending discoverer callbacks have run before the module text goes away.
Reachable from an unprivileged user namespace: the TIPCv2 genl family is netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP.
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149) Read of size 8 at addr ffff88802348b728 by task poc_tipc/184 <IRQ> tipc_disc_rcv (net/tipc/discover.c:149) tipc_rcv (net/tipc/node.c:2126) tipc_udp_recv (net/tipc/udp_media.c:391) udp_rcv (net/ipv4/udp.c:2643) ip_local_deliver_finish (net/ipv4/ip_input.c:241) </IRQ> Freed by task 181: kfree (mm/slub.c:6565) bearer_disable (net/tipc/bearer.c:418) tipc_nl_bearer_disable (net/tipc/bearer.c:1001)
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1005Data from Local Systemcollection60 %
Vulnerabilidad de use-after-free en kernel Linux explotable desde espacio de usuario sin privilegios (PR:L en namespace) causando DoS por corrupción de memoria y lectura de datos sensibles del kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b
- https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5
- https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98
- https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101
- https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2
- https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253
- https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f
- https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64543",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "380413cdfd29fb9fa486c82889132b680c4983c5",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "f05b3f4c78370469286879c765f5a1dd39dbcd32",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "4da2ac7749411971e1b222b992da5a172ce45f98",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "5e215bf1c47fdddf8203a0fe80a0ed594065f101",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "ec7d54d8cc1723921d671e3272b427c96366506f",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "b65289e1c3f352a9f92c6e19713ddd647e033253",
"versionType": "git"
},
{
"status": "affected",
"version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
"lessThan": "1579342d71133da7f00daa02c75cebec7372097b",
"versionType": "git"
}
],
"programFiles": [
"net/tipc/core.c",
"net/tipc/discover.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/tipc/core.c",
"net/tipc/discover.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-27T21:17:06.850",
"references": [
{
"url": "https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),\nbut tipc_disc_rcv() still dereferences b->disc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n <IRQ>\n tipc_disc_rcv (net/tipc/discover.c:149)\n tipc_rcv (net/tipc/node.c:2126)\n tipc_udp_recv (net/tipc/udp_media.c:391)\n udp_rcv (net/ipv4/udp.c:2643)\n ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n </IRQ>\n Freed by task 181:\n kfree (mm/slub.c:6565)\n bearer_disable (net/tipc/bearer.c:418)\n tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP."
}
],
"lastModified": "2026-08-19T17:20:15.650",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}