{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64015","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.027Z","datePublished":"2026-07-19T15:39:10.557Z","dateUpdated":"2026-08-05T12:38:12.353Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:38:12.353Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsecurity/keys: fix missed RCU read section on lookup\n\nNicholas Carlini reports that the keyring code calls assoc_array_find()\nin find_key_to_update() without holding the RCU read lock, while the\nassoc_array_gc() code really is designed around removing the node from\nthe tree and then freeing it after an RCU grace-period.\n\nThe regular key handling doesn't see this because holding the keyring\nsemaphore hides any lifetime issues, but the persistent key handling\nuses a different model.\n\nInstead of extending the keyring locking, just do the simple RCU locking\nthat the assoc_array was designed for."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through find_key_to_update() on the persistent keyring register, which is invoked from keyctl_get_persistent() via the keyctl(2) syscall. There is no network, adjacent-radio, or physical-device path to this code.\nAC:L - Exploitation is a race between assoc_array_find() and assoc_array_gc() on the .persistent_register keyring; the attacker controls both sides by repeatedly calling KEYCTL_GET_PERSISTENT (including from multiple threads) while driving key expiry/GC via keyctl timeouts or natural garbage collection. Per kernel guidance, attacker-controlled races are AC:L.\nPR:L - Any unprivileged local user who can invoke keyctl() can call KEYCTL_GET_PERSISTENT for their own UID (-1) with a writable destination keyring (e.g., session keyring). No real-root or CAP_SETUID capability is required for the vulnerable lookup path; this remains PR:L even inside user namespaces.\nUI:N - Exploitation requires only the attacker's own keyctl syscalls and does not depend on any victim user action such as mounting a filesystem or opening a file.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security domain; it does not cross a VM, container, or IOMMU boundary on its own.\nC:H - assoc_array_find() is documented to require an RCU read lock, but the persistent-keyring path called it without one while assoc_array_gc() frees tree nodes via call_rcu(), yielding a use-after-free on assoc_array nodes/leaves. UAF on kernel heap objects can be turned into arbitrary kernel memory reads.\nI:H - The freed assoc_array nodes can be reallocated and corrupted through concurrent GC versus lookup, providing a standard kernel heap UAF primitive that can be developed into arbitrary write or code-execution primitives.\nA:H - Dereferencing RCU-freed assoc_array tree nodes during lookup can cause kernel oops/panic from invalid pointer access, and UAF exploitation commonly destabilizes or crashes the kernel even when full exploitation is not attempted."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["security/keys/keyring.c"],"versions":[{"version":"b2a4df200d570b2c33a57e1ebfa5896e4bc81b69","lessThan":"4c5d407ba3ff7f30561ff73ba1b07ed70c864edc","status":"affected","versionType":"git"},{"version":"b2a4df200d570b2c33a57e1ebfa5896e4bc81b69","lessThan":"cefa4265b11176c897a7d9e8e54d89e3701c5584","status":"affected","versionType":"git"},{"version":"b2a4df200d570b2c33a57e1ebfa5896e4bc81b69","lessThan":"5659e6923cb72f8e18e8b539109ab512455fe195","status":"affected","versionType":"git"},{"version":"b2a4df200d570b2c33a57e1ebfa5896e4bc81b69","lessThan":"50bb3435a5e627bfbdc52eb4536f49f88b3486b8","status":"affected","versionType":"git"},{"version":"b2a4df200d570b2c33a57e1ebfa5896e4bc81b69","lessThan":"66288dcadf80974436250e9f70ed848836b835b5","status":"affected","versionType":"git"},{"version":"b2a4df200d570b2c33a57e1ebfa5896e4bc81b69","lessThan":"43a1e3744548e6fd85873e6fb43e293eb4010694","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["security/keys/keyring.c"],"versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.6.142"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4c5d407ba3ff7f30561ff73ba1b07ed70c864edc"},{"url":"https://git.kernel.org/stable/c/cefa4265b11176c897a7d9e8e54d89e3701c5584"},{"url":"https://git.kernel.org/stable/c/5659e6923cb72f8e18e8b539109ab512455fe195"},{"url":"https://git.kernel.org/stable/c/50bb3435a5e627bfbdc52eb4536f49f88b3486b8"},{"url":"https://git.kernel.org/stable/c/66288dcadf80974436250e9f70ed848836b835b5"},{"url":"https://git.kernel.org/stable/c/43a1e3744548e6fd85873e6fb43e293eb4010694"}],"title":"security/keys: fix missed RCU read section on lookup","x_generator":{"engine":"bippy-1.2.0"}}}}