« Volver al listado

CVE-2026-74661

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

mac802154: fix netdev use-after-free in beacon worker

mac802154_beacon_worker() reads local->beacon_req under RCU and derives the sub-interface from the request, but then drops the RCU read lock and continues to use both sdata and the embedded wpan_dev.

mac802154_stop_beacons_locked() cancels only pending beacon work, clears local->beacon_req and frees the request. A beacon worker that is already running can therefore continue after interface teardown and dereference the freed netdev private area.

The scan worker already pins the netdev before leaving RCU. Apply the same lifetime rule to the beacon worker: take a netdev reference while the request is still protected by RCU, and release it on all paths that continue after the reference is acquired.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local de use-after-free en kernel Linux (AV:L, PR:L) permitiendo DoS por crash de netdev y potencial corrupción de memoria tras liberación. Acceso local sin interacción del usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74661",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
              "lessThan": "fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
              "lessThan": "e5fb0e03bc7f45508c182a427357bf6b389a9033",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
              "lessThan": "e6cd416a899edc912b428c4ba399bd73f516cb31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
              "lessThan": "9d067e581597c462c51fee8a30b51bc48a68c4e1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3accf4762734a69ebd03cba989249c78ac7dfc7e",
              "lessThan": "5f26a690e8efa54315e4922368daf54e0b8f5515",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/mac802154/scan.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/mac802154/scan.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:39.883",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5f26a690e8efa54315e4922368daf54e0b8f5515",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9d067e581597c462c51fee8a30b51bc48a68c4e1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e5fb0e03bc7f45508c182a427357bf6b389a9033",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6cd416a899edc912b428c4ba399bd73f516cb31",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: fix netdev use-after-free in beacon worker\n\nmac802154_beacon_worker() reads local->beacon_req under RCU and derives\nthe sub-interface from the request, but then drops the RCU read lock and\ncontinues to use both sdata and the embedded wpan_dev.\n\nmac802154_stop_beacons_locked() cancels only pending beacon work, clears\nlocal->beacon_req and frees the request.  A beacon worker that is already\nrunning can therefore continue after interface teardown and dereference\nthe freed netdev private area.\n\nThe scan worker already pins the netdev before leaving RCU.  Apply the\nsame lifetime rule to the beacon worker: take a netdev reference while\nthe request is still protected by RCU, and release it on all paths that\ncontinue after the reference is acquired."
    }
  ],
  "lastModified": "2026-08-25T06:18:47.263",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}