{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64543","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.795Z","datePublished":"2026-07-27T20:10:35.565Z","dateUpdated":"2026-08-19T16:28:28.342Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:28:28.342Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),\nbut tipc_disc_rcv() still dereferences b->disc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n <IRQ>\n  tipc_disc_rcv (net/tipc/discover.c:149)\n  tipc_rcv (net/tipc/node.c:2126)\n  tipc_udp_recv (net/tipc/udp_media.c:391)\n  udp_rcv (net/ipv4/udp.c:2643)\n  ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n </IRQ>\n Freed by task 181:\n  kfree (mm/slub.c:6565)\n  bearer_disable (net/tipc/bearer.c:418)\n  tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The free side is only reachable through the local TIPCv2 generic-netlink `BEARER_DISABLE` command (or netns teardown); a remote peer can supply the discovery packet that performs the use-after-free access but cannot itself cause `bearer_disable()` to run, so the complete attack requires local access.\nAC:L - The attacker controls both sides of the race — one thread floods TIPC discovery packets at the bearer's UDP port while another disables the bearer — and `bearer_disable()` clears `b->up` and then `kfree()`s the discoverer with no synchronization whatsoever, leaving a wide window that a multi-CPU packet flood hits reliably (a working PoC exists).\nPR:L - `tipc_genl_family` is `.netnsok = true` and the bearer enable/disable ops carry no `GENL_ADMIN_PERM` or other capability check, so an unprivileged user can do everything inside `unshare -Urn` after autoloading tipc via `socket(AF_TIPC, ...)`.\nUI:N - The attacking process performs both the bearer disable and the packet injection itself; no victim action or cooperating user is involved.\nS:U - The corruption stays within the kernel's own security authority — no VM, IOMMU, or hypervisor boundary is crossed.\nC:H - `d->net` is read from the freed slab object and dereferenced as a `struct net *`; after reclaiming the kmalloc-192 allocation with sprayed data the attacker gains a controlled-pointer dereference chain usable for arbitrary kernel memory disclosure.\nI:H - `msg_set_prevnode(buf_msg(d->skb), sugg_addr)` writes a wire-controlled 32-bit value through the dangling `d->skb` pointer, and `tipc_disc_add_dest()` takes a spinlock and increments a counter in freed memory — together a controlled-address/controlled-value write suitable for control-flow hijacking.\nA:H - The use-after-free reliably produces a KASAN slab-use-after-free in softirq context and, on production kernels, a corrupted-pointer dereference or spinlock manipulation on reclaimed memory leading to kernel panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/tipc/core.c","net/tipc/discover.c"],"versions":[{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"380413cdfd29fb9fa486c82889132b680c4983c5","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"f05b3f4c78370469286879c765f5a1dd39dbcd32","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"4da2ac7749411971e1b222b992da5a172ce45f98","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"5e215bf1c47fdddf8203a0fe80a0ed594065f101","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"ec7d54d8cc1723921d671e3272b427c96366506f","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"b65289e1c3f352a9f92c6e19713ddd647e033253","status":"affected","versionType":"git"},{"version":"25b0b9c4e835ffaa65b61c3efe2e28acf84d0259","lessThan":"1579342d71133da7f00daa02c75cebec7372097b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/tipc/core.c","net/tipc/discover.c"],"versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5"},{"url":"https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32"},{"url":"https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98"},{"url":"https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101"},{"url":"https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f"},{"url":"https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2"},{"url":"https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253"},{"url":"https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b"}],"title":"tipc: fix use-after-free of the discoverer in tipc_disc_rcv()","x_generator":{"engine":"bippy-1.2.0"}}}}