« Volver al listado

CVE-2026-97599

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: hwsim: serialize pib updates to fix double-free

hwsim_update_pib() does an unserialized read-swap-free of phy->pib:

It assumes the RTNL is held, but ->set_channel is not always called under it: the mac802154 scan worker changes channels via drv_set_channel() without the RTNL. Such an update can race an RTNL-held one on the same phy; both read the same pib_old and both kfree_rcu() it, double-freeing the object. With SLUB percpu sheaves batching kfree_rcu(), this surfaces as a KASAN invalid-free in rcu_free_sheaf().

struct hwsim_phy has no lock for pib. Add one and make the swap atomic with rcu_replace_pointer() under it, dropping the misleading rtnl_dereference().

Detalles técnicos trazas, registros y código del informe original
	pib_old = rtnl_dereference(phy->pib);
	...
	rcu_assign_pointer(phy->pib, pib);
	kfree_rcu(pib_old, rcu);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97599",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f25da51fdc381ca2863248c7060b3662632f0872",
              "lessThan": "e3b4681197aa026bd2d79358de5a3d62b76b04b9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f25da51fdc381ca2863248c7060b3662632f0872",
              "lessThan": "9973b3a67a7592a780ea12b08334539a900deec1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f25da51fdc381ca2863248c7060b3662632f0872",
              "lessThan": "d3b8f264ce09573aededd0a97dc41c8147797d8f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f25da51fdc381ca2863248c7060b3662632f0872",
              "lessThan": "db6442deecb1f13aeaf4f9d77746ea7555630fb3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f25da51fdc381ca2863248c7060b3662632f0872",
              "lessThan": "979d5b8de8ed4e1f997aef12da5694b99be7b871",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ieee802154/mac802154_hwsim.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ieee802154/mac802154_hwsim.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:11.243",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/979d5b8de8ed4e1f997aef12da5694b99be7b871",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9973b3a67a7592a780ea12b08334539a900deec1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d3b8f264ce09573aededd0a97dc41c8147797d8f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/db6442deecb1f13aeaf4f9d77746ea7555630fb3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3b4681197aa026bd2d79358de5a3d62b76b04b9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: hwsim: serialize pib updates to fix double-free\n\nhwsim_update_pib() does an unserialized read-swap-free of phy->pib:\n\n\tpib_old = rtnl_dereference(phy->pib);\n\t...\n\trcu_assign_pointer(phy->pib, pib);\n\tkfree_rcu(pib_old, rcu);\n\nIt assumes the RTNL is held, but ->set_channel is not always called\nunder it: the mac802154 scan worker changes channels via\ndrv_set_channel() without the RTNL. Such an update can race an\nRTNL-held one on the same phy; both read the same pib_old and both\nkfree_rcu() it, double-freeing the object. With SLUB percpu sheaves\nbatching kfree_rcu(), this surfaces as a KASAN invalid-free in\nrcu_free_sheaf().\n\nstruct hwsim_phy has no lock for pib. Add one and make the swap atomic\nwith rcu_replace_pointer() under it, dropping the misleading\nrtnl_dereference()."
    }
  ],
  "lastModified": "2026-10-03T11:18:06.467",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}