CVE-2026-80849
In the Linux kernel, the following vulnerability has been resolved:
net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
tcp_inbound_ao_hash() is called before bh_lock_sock_nested() is taken, with only rcu_read_lock() held. On the fast path for established sockets, if the rnext_keyid sent by the peer differs from current_key->sndid, the key the peer asked for is looked up and stored in current_key. The lookup is inside the RCU read side, but current_key outlives it.
When the socket is disconnected and connect() is called again for another peer, tcp_ao_connect_init() unlinks every key that does not match the new peer and frees it with call_rcu(). If current_key points at such a key, it is cleared to NULL.
Leer descripción completaMostrar menos
The fast path reads sk_state only once on entry, so a softirq that got into it while the socket was still established can update current_key after that loop has already run. The update is inside the RCU read side, so it comes before the call_rcu() callback, and once the callback frees the key, current_key is left pointing at freed memory.
The next transmission picks that pointer up in tcp_get_current_key(). tcp_ao_transmit_skb() then reads the traffic key from the freed object, which is the use-after-free.
Wait for one grace period before unlinking, and only if a key is going to be removed. By the time tcp_connect() runs the socket is already in TCP_SYN_SENT, and TCP_AO_ESTABLISHED does not contain TCPF_SYN_SENT, so a softirq entering after the wait cannot reach the fast path, and the ones already in it have finished. The existing NULL handling in the loop is then enough.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2857dcbd03cf3354af0fba1b65c6a260fb43811a
- https://git.kernel.org/stable/c/73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3
- https://git.kernel.org/stable/c/84a93b4e012587d0a4a84ffb23ec6da18e9d85f9
- https://git.kernel.org/stable/c/da4471557f279d0f56605158a625bb6e49ef7d41
- https://git.kernel.org/stable/c/e54ad693eddb40c595add013f545354c538e325b
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80849",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0a3a809089eb1d4a0a2fd0c16b520d603988c859",
"lessThan": "84a93b4e012587d0a4a84ffb23ec6da18e9d85f9",
"versionType": "git"
},
{
"status": "affected",
"version": "0a3a809089eb1d4a0a2fd0c16b520d603988c859",
"lessThan": "73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3",
"versionType": "git"
},
{
"status": "affected",
"version": "0a3a809089eb1d4a0a2fd0c16b520d603988c859",
"lessThan": "e54ad693eddb40c595add013f545354c538e325b",
"versionType": "git"
},
{
"status": "affected",
"version": "0a3a809089eb1d4a0a2fd0c16b520d603988c859",
"lessThan": "2857dcbd03cf3354af0fba1b65c6a260fb43811a",
"versionType": "git"
},
{
"status": "affected",
"version": "0a3a809089eb1d4a0a2fd0c16b520d603988c859",
"lessThan": "da4471557f279d0f56605158a625bb6e49ef7d41",
"versionType": "git"
}
],
"programFiles": [
"net/ipv4/tcp_ao.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/ipv4/tcp_ao.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T16:18:13.683",
"references": [
{
"url": "https://git.kernel.org/stable/c/2857dcbd03cf3354af0fba1b65c6a260fb43811a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/84a93b4e012587d0a4a84ffb23ec6da18e9d85f9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/da4471557f279d0f56605158a625bb6e49ef7d41",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e54ad693eddb40c595add013f545354c538e325b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp-ao: fix use-after-free of current_key on reconnect to another peer\n\ntcp_inbound_ao_hash() is called before bh_lock_sock_nested() is taken,\nwith only rcu_read_lock() held. On the fast path for established\nsockets, if the rnext_keyid sent by the peer differs from\ncurrent_key->sndid, the key the peer asked for is looked up and stored\nin current_key. The lookup is inside the RCU read side, but current_key\noutlives it.\n\nWhen the socket is disconnected and connect() is called again for\nanother peer, tcp_ao_connect_init() unlinks every key that does not\nmatch the new peer and frees it with call_rcu(). If current_key points\nat such a key, it is cleared to NULL.\n\nThe fast path reads sk_state only once on entry, so a softirq that got\ninto it while the socket was still established can update current_key\nafter that loop has already run. The update is inside the RCU read side,\nso it comes before the call_rcu() callback, and once the callback frees\nthe key, current_key is left pointing at freed memory.\n\nThe next transmission picks that pointer up in tcp_get_current_key().\ntcp_ao_transmit_skb() then reads the traffic key from the freed object,\nwhich is the use-after-free.\n\nWait for one grace period before unlinking, and only if a key is going\nto be removed. By the time tcp_connect() runs the socket is already in\nTCP_SYN_SENT, and TCP_AO_ESTABLISHED does not contain TCPF_SYN_SENT, so\na softirq entering after the wait cannot reach the fast path, and the\nones already in it have finished. The existing NULL handling in the loop\nis then enough."
}
],
"lastModified": "2026-09-04T16:18:13.683",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}