{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80995","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.812Z","datePublished":"2026-09-11T19:42:50.866Z","dateUpdated":"2026-09-13T06:28:58.816Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:28:58.816Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: hold a reference to the route device in mctp_route_lookup()\n\nmctp_route_lookup() uses rt->dev without holding a reference on it.\nmctp_route_lookup_single() returns the route under RCU only, so the\nroute's device can be torn down concurrently: mctp_dev_put() drops the\nlast reference and synchronously kfree()s mdev->addrs.  mctp_dev_saddr()\nthen reads rt->dev->addrs[0], giving a use-after-free reachable by an\nunprivileged local AF_MCTP user on the receive/forwarding path (no\nCAP_NET_RAW required):\n\n  BUG: KASAN: slab-use-after-free in mctp_route_lookup\n  Read of size 1 at addr ... by task mctp_uaf/...\n   mctp_route_lookup\n   mctp_pkttype_receive\n  Freed by task ...:\n   kfree\n   mctp_dev_put\n   mctp_dev_notify\n\nIn the same window mctp_dst_from_route() -> mctp_dev_hold() also\nincrements a refcount that has already reached zero\n(\"refcount_t: addition on 0 ... mctp_dev_hold\").\n\nThis reintroduces the use-after-free class of CVE-2023-3439: the source\naddress lookup was moved ahead of the point where the destination takes\nits device reference.\n\nTake a reference with refcount_inc_not_zero() before touching rt->dev,\nskip a device that is already dead, and drop the reference once the\ndestination has taken its own."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached when mctp_pkttype_receive() calls mctp_route_lookup() while the route device is destroyed via mctp_dev_notify()/NETDEV_UNREGISTER. An unprivileged local user can create a TUN (ARPHRD_NONE auto-attaches mctp_dev), inject ETH_P_MCTP frames, and delete that netdev; this is a local syscall/netlink path, not a remote IP service.\nAC:L - The attacker controls both sides of the race by injecting MCTP packets on one thread and unregistering the TUN/MCTP netdev on another, and can retry until mctp_dev_saddr() runs after mctp_dev_put() has synchronously kfree'd mdev->addrs.\nPR:L - TUN creation, MCTP address/route setup, and netdev teardown require CAP_NET_ADMIN, which an unprivileged user obtains in a user+net namespace. The receive/forwarding path has no CAP_NET_RAW check, unlike mctp_sendmsg().\nUI:N - Exploitation requires no victim action; the attacker alone creates the interface, injects frames, and tears it down.\nS:U - Impact is in-kernel use-after-free and local privilege escalation within the same kernel security authority; no VM escape, IOMMU bypass, or sandbox boundary is crossed.\nC:H - This is a use-after-free of mdev->addrs (and a dangling mctp_dev after refcount-add-on-0); UAF of a kmalloc object enables heap reuse and arbitrary kernel memory disclosure.\nI:H - After the last reference is dropped, mctp_dst_from_route() still calls mctp_dev_hold() and later dst.output() uses the freed device; reclaiming that object yields an arbitrary write and control-flow hijack primitive.\nA:H - KASAN reports a slab-use-after-free in mctp_route_lookup and a refcount_t addition-on-0 in mctp_dev_hold; the UAF reliably oopses or panics the kernel even when not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mctp/route.c"],"versions":[{"version":"22cb45afd221b9e4f2a1dcc74a8ff645b7293aa1","lessThan":"cc561f8af25586300c2f9d285babb163b866b293","status":"affected","versionType":"git"},{"version":"22cb45afd221b9e4f2a1dcc74a8ff645b7293aa1","lessThan":"408da1df18116c971c3392e21e50586688cd3fbf","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mctp/route.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/cc561f8af25586300c2f9d285babb163b866b293"},{"url":"https://git.kernel.org/stable/c/408da1df18116c971c3392e21e50586688cd3fbf"}],"title":"net: mctp: hold a reference to the route device in mctp_route_lookup()","x_generator":{"engine":"bippy-1.2.0"}}}}