CVE-2026-74513
In the Linux kernel, the following vulnerability has been resolved:
dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
dibs_lo_attach_dmb(), dibs_lo_detach_dmb() and dibs_lo_unregister_dmb() look up the dmb_node under dmb_ht_lock, drop the lock and only then operate on the node's refcount. Nothing keeps the node alive across that window: __dibs_lo_unregister_dmb() removes the node from the hash table under the write lock and immediately frees it.
A concurrent final put can therefore free the node between the lookup and the refcount operation:
CPU0 (attach) CPU1 (owner unregisters)
Leer descripción completaMostrar menos
The same window exists for the refcount_dec_and_test() calls in the detach and unregister paths.
Close the race structurally by making hash table membership and the refcount transitions atomic with respect to each other:
__dibs_lo_unregister_dmb() no longer touches the hash table and is renamed to dibs_lo_free_dmb() accordingly.
Note: commit cc21191b584c ("dibs: Move data path to dibs layer") moved the code to its current location; the race was introduced earlier by commit c3a910f2380f ("net/smc: implement DMB-merged operations of loopback-ism").
Tested SMC-D via ISM and dibs loopback.
Detalles técnicos trazas, registros y código del informe original
read_lock_bh(&dmb_ht_lock)
find dmb_node (refcnt == 1)
read_unlock_bh(&dmb_ht_lock)
refcount_dec_and_test() 1 -> 0
write_lock_bh(&dmb_ht_lock)
hash_del(&dmb_node->list)
write_unlock_bh(&dmb_ht_lock)
kfree(dmb_node)
refcount_inc_not_zero(&dmb_node->refcnt) <-- use-after-free
- Perform the final refcount_dec_and_test() and hash_del() in a single
dmb_ht_lock write-side critical section, in both the unregister and
the detach path. Freeing the node still happens after the lock is
dropped, which is safe because a node whose refcount reached zero has
left the hash table and can no longer be found.
- This establishes the invariant that any node found in the hash table
holds at least one reference, and that the final reference can only
be dropped under the write lock. dibs_lo_attach_dmb() can thus take
its reference with a plain refcount_inc() while still holding the
read lock; refcount_inc_not_zero() is no longer needed.CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1565.001Stored Data Manipulationimpact65 %
AV:L + PR:L + acceso local con privilegios. Use-after-free en kernel Linux permite DoS por corrupción de memoria y potencial manipulación de datos en operaciones DMB.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74513",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c3a910f2380fe294d14e42af66af3d3eed8fecbf",
"lessThan": "c0837aeace96152d14b17fdd19d70102b6631a7d",
"versionType": "git"
},
{
"status": "affected",
"version": "c3a910f2380fe294d14e42af66af3d3eed8fecbf",
"lessThan": "48c073f88c93707089a4214f21cb4c3de5aea6e4",
"versionType": "git"
},
{
"status": "affected",
"version": "c3a910f2380fe294d14e42af66af3d3eed8fecbf",
"lessThan": "a10ea943356b9d70c5616a0a06f6fa97cfdaccb1",
"versionType": "git"
}
],
"programFiles": [
"drivers/dibs/dibs_loopback.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/dibs/dibs_loopback.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T13:17:56.410",
"references": [
{
"url": "https://git.kernel.org/stable/c/48c073f88c93707089a4214f21cb4c3de5aea6e4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a10ea943356b9d70c5616a0a06f6fa97cfdaccb1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c0837aeace96152d14b17fdd19d70102b6631a7d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndibs: fix use-after-free of dmb_node in loopback attach/detach/unregister\n\ndibs_lo_attach_dmb(), dibs_lo_detach_dmb() and dibs_lo_unregister_dmb()\nlook up the dmb_node under dmb_ht_lock, drop the lock and only then\noperate on the node's refcount. Nothing keeps the node alive across\nthat window: __dibs_lo_unregister_dmb() removes the node from the hash\ntable under the write lock and immediately frees it.\n\nA concurrent final put can therefore free the node between the lookup\nand the refcount operation:\n\nCPU0 (attach) CPU1 (owner unregisters)\n\nread_lock_bh(&dmb_ht_lock)\nfind dmb_node (refcnt == 1)\nread_unlock_bh(&dmb_ht_lock)\n refcount_dec_and_test() 1 -> 0\n write_lock_bh(&dmb_ht_lock)\n hash_del(&dmb_node->list)\n write_unlock_bh(&dmb_ht_lock)\n kfree(dmb_node)\nrefcount_inc_not_zero(&dmb_node->refcnt) <-- use-after-free\n\nThe same window exists for the refcount_dec_and_test() calls in the\ndetach and unregister paths.\n\nClose the race structurally by making hash table membership and the\nrefcount transitions atomic with respect to each other:\n\n- Perform the final refcount_dec_and_test() and hash_del() in a single\n dmb_ht_lock write-side critical section, in both the unregister and\n the detach path. Freeing the node still happens after the lock is\n dropped, which is safe because a node whose refcount reached zero has\n left the hash table and can no longer be found.\n\n- This establishes the invariant that any node found in the hash table\n holds at least one reference, and that the final reference can only\n be dropped under the write lock. dibs_lo_attach_dmb() can thus take\n its reference with a plain refcount_inc() while still holding the\n read lock; refcount_inc_not_zero() is no longer needed.\n\n__dibs_lo_unregister_dmb() no longer touches the hash table and is\nrenamed to dibs_lo_free_dmb() accordingly.\n\nNote: commit cc21191b584c (\"dibs: Move data path to dibs layer\") moved\nthe code to its current location; the race was introduced earlier by\ncommit c3a910f2380f (\"net/smc: implement DMB-merged operations of\nloopback-ism\").\n\nTested SMC-D via ISM and dibs loopback."
}
],
"lastModified": "2026-08-17T06:19:48.007",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}