{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81001","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.812Z","datePublished":"2026-09-11T19:42:54.846Z","dateUpdated":"2026-09-14T11:59:36.376Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:36.376Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nslip: fix use-after-free in sl_sync()\n\nslip_devs[] stores bare net_device pointers and takes no reference on\nthem.  sl_sync() and sl_alloc() walk that table from slip_open() under\nrtnl_lock(), while an entry is dropped by sl_free_netdev(), which\nsl_setup() installs as dev->priv_destructor.\n\npriv_destructor is called from netdev_run_todo(), which deliberately\nruns with the RTNL semaphore released so that it can sleep while waiting\nfor the device refcount to drop:\n\n\t/* Snapshot list, allow later requests */\n\tlist_replace_init(&net_todo_list, &list);\n\n\t__rtnl_unlock();\n\t...\n\t\tif (dev->priv_destructor)\n\t\t\tdev->priv_destructor(dev);\t/* slip_devs[i] = NULL */\n\t\tif (dev->needs_free_netdev)\n\t\t\tfree_netdev(dev);\n\t\t...\n\t\t/* Free network device */\n\t\tkobject_put(&dev->dev.kobj);\n\nSo rtnl_lock() does not serialise slip_open() against the teardown at\nall.  sl_sync() can load slip_devs[i] while the entry is still published\nand dereference it after netdev_run_todo() has run the destructor and\nreleased the device:\n\n  CPU0 (slip_open)                 CPU1 (slip_close)\n                                   unregister_netdev()\n                                     rtnl_unlock()\n                                       netdev_run_todo()\n                                         __rtnl_unlock()\n  rtnl_lock()\n  sl_sync()\n    dev = slip_devs[i]\n                                         priv_destructor(dev)\n                                           slip_devs[i] = NULL\n                                         kobject_put(&dev->dev.kobj)\n                                           /* dev is freed */\n    sl = netdev_priv(dev)\n    if (sl->tty || sl->leased)     /* use-after-free */\n\n  BUG: KASAN: use-after-free in sl_sync drivers/net/slip/slip.c:730 [inline]\n  BUG: KASAN: use-after-free in slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806\n  Read of size 1 at addr ffff8880712dac71 by task syz-executor.2/6506\n\n  CPU: 2 PID: 6506 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00260-g0c8fc3469765 #0\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\n  Call Trace:\n   sl_sync drivers/net/slip/slip.c:730 [inline]\n   slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806\n   tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433\n   tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564\n   tiocsetd drivers/tty/tty_io.c:2428 [inline]\n   tty_ioctl+0x5f0/0x1530 drivers/tty/tty_io.c:2712\n\n  Allocated by task 6502:\n   alloc_netdev_mqs+0x98/0xfe0 net/core/dev.c:10719\n   sl_alloc drivers/net/slip/slip.c:756 [inline]\n   slip_open+0x36d/0x1210 drivers/net/slip/slip.c:817\n   tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433\n   tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564\n\n  Freed by task 6497:\n   device_release+0xa2/0x240 drivers/base/core.c:2507\n   kobject_put+0x179/0x280 lib/kobject.c:729\n   netdev_run_todo+0x6c8/0xef0 net/core/dev.c:10509\n   slip_close+0x166/0x1c0 drivers/net/slip/slip.c:906\n   tty_ldisc_close+0x113/0x1a0 drivers/tty/tty_ldisc.c:456\n   tty_ldisc_kill+0x94/0x160 drivers/tty/tty_ldisc.c:614\n   tty_ldisc_release+0xe3/0x2b0 drivers/tty/tty_ldisc.c:782\n   tty_release+0xbcc/0xe70 drivers/tty/tty_io.c:1860\n\nCommit e58c19124189 (\"slip: Fix use-after-free Read in slip_open\") fixed\na different source of stale entries - a device left in slip_devs[] after\nslip_open() freed it on the registration error path - and does not\naddress this race, which is why the report survives it.\n\nDrop the entry from ndo_uninit instead.  unregister_netdevice() calls\nndo_uninit under RTNL, before the device is queued to netdev_run_todo(),\nso an entry that sl_sync() can still see while holding RTNL belongs to a\ndevice that cannot be freed until RTNL is dropped.  sl_free_netdev()\nstays only for the slip_open() error path, where register_netdevice()\nmay have failed before ndo_init and ndo_uninit is then not called\neither.  Both running for the same device is harmless: the\n---truncated---"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached only via local TTY syscalls: open(\"/dev/ptmx\") then ioctl(TIOCSETD, N_SLIP) into tty_ioctl→tiocsetd→tty_set_ldisc→slip_open→sl_sync, raced with close()→slip_close→unregister_netdev. sl_sync() is not on the packet-receive path, so the vector is Local rather than Network or Physical.\nAC:L - The attacker controls both sides of the race, looping open(ptmx)+TIOCSETD(N_SLIP)+close() on several threads as in the syzkaller reproducer. netdev_run_todo() drops RTNL during attacker-initiated teardown, so winning the window does not depend on victim state or other uninfluenceable timing.\nPR:L - slip_open() requires capable(CAP_NET_ADMIN), which checks init_user_ns and is not granted by unshare -Urn. CAP_NET_ADMIN in the initial user namespace is still routinely delegated to non-root container and network workloads (Docker/K8s --cap-add=NET_ADMIN, CNI/VPN sidecars) without full host root, so privileges required are Low.\nUI:N - The attacker performs every step—opening PTYs, attaching N_SLIP, and closing fds—in its own processes. No separate victim user or administrator action is required at exploit time.\nS:U - The UAF corrupts a host-kernel net_device from alloc_netdev() and remains inside that kernel’s security authority. Impact is standard local privilege escalation, not a VM escape or IOMMU/DMA boundary bypass.\nC:H - sl_sync() dereferences a freed net_device and its embedded struct slip (netdev_priv). Per kernel CNA guidance a use-after-free lets the attacker control the freed object via heap spray, yielding an arbitrary kernel read primitive.\nI:H - After the UAF load, sl_sync() may call dev_close() on the freed or reused net_device, exercising netdev_ops and related kernel state. That is a use-after-free of an object with function pointers, enabling arbitrary writes and control-flow hijacking.\nA:H - Use-after-free of the SLIP net_device causes a kernel oops or panic even when not fully exploited; KASAN reported a slab-use-after-free in sl_sync() on the syzkaller reproducer."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/slip/slip.c"],"versions":[{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"045e307ac21fbd735b789d8817b21be4d8ead054","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"87398cdec8bdf84096a8af4dbccdb04f1972f32c","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"e93ace1f46177a4f7b5a8e5996606cdf77e1e890","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"70e20456bcbf7f3ae145bb96e5548f827a37c640","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"a235b20972bbd98ca1fb127d6269434edc607f19","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"486577db807891d0f964fdf13c1640c7f54b0ad1","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"d6f25e5bd777b05880da8673daf74a8419480545","status":"affected","versionType":"git"},{"version":"5342b77c4123ba39f911d92a813295fb3bb21f69","lessThan":"2c4e7c42d77e78ad595dbb9e4b5886b58b45d89d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/slip/slip.c"],"versions":[{"version":"2.6.32","status":"affected"},{"version":"0","lessThan":"2.6.32","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/045e307ac21fbd735b789d8817b21be4d8ead054"},{"url":"https://git.kernel.org/stable/c/87398cdec8bdf84096a8af4dbccdb04f1972f32c"},{"url":"https://git.kernel.org/stable/c/e93ace1f46177a4f7b5a8e5996606cdf77e1e890"},{"url":"https://git.kernel.org/stable/c/70e20456bcbf7f3ae145bb96e5548f827a37c640"},{"url":"https://git.kernel.org/stable/c/a235b20972bbd98ca1fb127d6269434edc607f19"},{"url":"https://git.kernel.org/stable/c/486577db807891d0f964fdf13c1640c7f54b0ad1"},{"url":"https://git.kernel.org/stable/c/d6f25e5bd777b05880da8673daf74a8419480545"},{"url":"https://git.kernel.org/stable/c/2c4e7c42d77e78ad595dbb9e4b5886b58b45d89d"}],"title":"slip: fix use-after-free in sl_sync()","x_generator":{"engine":"bippy-1.2.0"}}}}