{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64459","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.789Z","datePublished":"2026-07-25T08:51:26.879Z","dateUpdated":"2026-08-17T04:56:03.943Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:56:03.943Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restore RCU grace period in tcp_ao_destroy_sock\n\nCommit 51e547e8c89c (\"tcp: Free TCP-AO/TCP-MD5 info/keys without RCU\")\nremoved the call_rcu() callback from tcp_ao_destroy_sock(), arguing that\n\"the destruction of info/keys is delayed until the socket destructor\"\nand therefore \"no one can discover it anymore\".\n\nThat argument does not hold for the call site in tcp_connect()\n(net/ipv4/tcp_output.c:4327-4332). At that point the socket is in\nTCP_SYN_SENT, has already been inserted into the inet ehash by\ninet_hash_connect() in tcp_v4_connect(), and is therefore very much\ndiscoverable: any softirq running tcp_v4_rcv() on another CPU can take\nthe socket out of the ehash, walk into tcp_inbound_hash(), and load\ntp->ao_info via implicit RCU before bh_lock_sock_nested() is taken on\nthe destroying CPU.\n\nThe reader path then enters __tcp_ao_do_lookup() (net/ipv4/tcp_ao.c:208)\nwhich re-loads tp->ao_info via rcu_dereference_check(); the re-load can\nstill observe the (about-to-be-freed) pointer because there is no\nsynchronize_rcu() between rcu_assign_pointer(tp->ao_info, NULL) and\ntcp_ao_info_free() in tcp_ao_destroy_sock(). The captured pointer is\nthen walked at line 223:\n\n\thlist_for_each_entry_rcu(key, &ao->head, node, ...)\n\nThe writer's synchronous kfree() is free to complete between the line\n218 re-fetch and the line 223 hlist iteration. The slab is reused\n(or simply LIST_POISON1-stamped if not yet reused) and the iteration\nwalks attacker-controlled or poison memory in softirq context.\n\nReproducer (no debug shim, stock x86_64 v7.1-rc2 SMP+KASAN, QEMU+KVM):\nan unprivileged uid=1000 process inside CLONE_NEWUSER|CLONE_NEWNET\ninstalls TCP_MD5SIG + TCP_AO_ADD_KEY on a TCP socket, sprays forged\nTCP-AO segments toward its eventual 4-tuple via raw sockets, then\ncalls connect(). The md5-wins reconciliation in tcp_connect() fires\ntcp_ao_destroy_sock(); the softirq backlog reader on the loopback\nNAPI path crashes on the freed ao->head.first walk:\n\n  Oops: general protection fault, probably for non-canonical\n    address 0xfbd59c000000002f\n  KASAN: maybe wild-memory-access in range\n    [0xdead000000000178-0xdead00000000017f]\n  CPU: 0 UID: 1000 PID: 100 Comm: repro_userns\n  RIP: 0010:__tcp_ao_do_lookup+0x107/0x1c0\n  Call Trace: <IRQ>\n    __tcp_ao_do_lookup+0x107/0x1c0\n    tcp_ao_inbound_lookup.constprop.0+0x12a/0x200\n    tcp_inbound_ao_hash+0x5ea/0x1520\n    tcp_inbound_hash+0x7ce/0x1240\n    tcp_v4_rcv+0x1e7a/0x3e10\n    ...\n\nRestore the RCU grace period: re-add struct rcu_head to tcp_ao_info\nand replace the synchronous tcp_ao_info_free() with a call_rcu()\ncallback. Readers that captured tp->ao_info before rcu_assign_pointer\nNULLed it now see the object remain valid until rcu_read_unlock().\nWith the patch applied the reproducer runs cleanly for 2000 iterations\non the same kernel build."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - Forged TCP-AO segments received by the TCP/IP stack reach the stale AO lookup while a mixed TCP-MD5/TCP-AO client socket is connecting. A remote peer can trigger the use-after-free before AO authentication occurs.\nAC:L - Continuous packet spraying across a known or fixed four-tuple can repeatedly cover the short post-ehash connection window. The race is attacker-influenceable and repeatable, including across automatic reconnects.\nPR:N - The stale AO list is traversed before tcp_ao_verify_hash validates the packet, so the remote sender needs neither a valid AO key nor target-system privileges.\nUI:N - No human action is required; an automatically reconnecting network daemon provides the necessary connection lifecycle.\nS:U - The vulnerable TCP-AO objects and resulting memory corruption belong to the same host-kernel security authority.\nC:H - The slab use-after-free permits attacker-influenced traversal of reclaimed list and key objects, potentially enabling arbitrary kernel-memory reads and disclosure.\nI:H - The receive path performs atomic counter writes through stale info or key pointers, and controlled reclamation can provide corruption primitives suitable for control-flow hijacking.\nA:H - The demonstrated race causes a wild-memory access and kernel oops in softirq context, potentially panicking or repeatedly crashing the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/tcp_ao.h","net/ipv4/tcp_ao.c"],"versions":[{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"657646c08c94ef7b9dbe468fe7828032216f9841","status":"affected","versionType":"git"},{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"4caf12c778fed3dc3824cf36263be5e2c491fbd0","status":"affected","versionType":"git"},{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"8bc4d43bccbd60efe85d0a44d5bf41762f2f0c30","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/tcp_ao.h","net/ipv4/tcp_ao.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/657646c08c94ef7b9dbe468fe7828032216f9841"},{"url":"https://git.kernel.org/stable/c/4caf12c778fed3dc3824cf36263be5e2c491fbd0"},{"url":"https://git.kernel.org/stable/c/8bc4d43bccbd60efe85d0a44d5bf41762f2f0c30"}],"title":"tcp: restore RCU grace period in tcp_ao_destroy_sock","x_generator":{"engine":"bippy-1.2.0"}}}}