{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81006","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.812Z","datePublished":"2026-09-11T19:42:58.111Z","dateUpdated":"2026-09-13T06:29:09.887Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:29:09.887Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Remove all sysfs files on registration failure\n\nipmi_add_smi() creates the nr_users and nr_msgs files before trying to\ncreate the maintenance_mode file. If that last creation fails, the error\npath removes only nr_users before dropping the final reference to the\ninterface.\n\nRemove nr_msgs as well so no sysfs attribute embedded in the freed\ninterface remains registered."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - ipmi_add_smi() is reached only from local host-side SMI probe (ipmi_si, ipmi_ssif, ipmi_ipmb, ipmi_powernv) and the dangling nr_msgs file is hit by local sysfs read(2); IPMI-over-LAN is BMC firmware and does not enter this kernel path.\nAC:L - A local attacker can force device_create_file(maintenance_mode) to fail after nr_msgs is installed (memory pressure, hotmod/bind retries), then every read of the leftover attribute is a deterministic use-after-free with no race the attacker cannot control.\nPR:L - DEVICE_ATTR_RO(nr_msgs) is mode 0444 and nr_msgs_show() has no capability check, so any unprivileged local user who can read sysfs can trigger the UAF after a failed SMI registration; this is not limited to init-namespace root and is not a pre-auth network path.\nUI:N - The attacker causes SMI registration failure and then reads the leftover nr_msgs sysfs file themselves; no separate victim action such as mounting a filesystem or opening a hostile file is required.\nS:U - The use-after-free is of host-kernel struct ipmi_smi and its embedded device_attribute; impact stays in the same kernel security authority with no VM, IOMMU, or sandbox boundary crossing.\nC:H - The leftover sysfs attribute is embedded in the kmalloc'd ipmi_smi that intf_free() kfree()s, so nr_msgs_show() container_of() and the users-list walk are a slab use-after-free that can be reclaimed for arbitrary kernel memory disclosure.\nI:H - sysfs dispatches through device_attribute.show stored in the freed ipmi_smi, and nr_msgs_show() takes users_mutex and walks intf->users on that object, enabling heap spray and control-flow hijack per kernel UAF guidance.\nA:H - Reading the dangling nr_msgs file dereferences freed ipmi_smi memory (mutex_lock and list traversal) and readily oopses or panics the kernel; any use-after-free is High availability impact even without full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"versions":[{"version":"627118470fccc61d7763aa667fcab0a9476843f6","lessThan":"d46c97eddcbc53ca885e8bb359930c58884616ff","status":"affected","versionType":"git"},{"version":"627118470fccc61d7763aa667fcab0a9476843f6","lessThan":"b115b7d06f26b3f000d2afda88acb54c7a7cb2c9","status":"affected","versionType":"git"},{"version":"627118470fccc61d7763aa667fcab0a9476843f6","lessThan":"b6c46ab0bdee90c238e96ea4a74972118c97900d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d46c97eddcbc53ca885e8bb359930c58884616ff"},{"url":"https://git.kernel.org/stable/c/b115b7d06f26b3f000d2afda88acb54c7a7cb2c9"},{"url":"https://git.kernel.org/stable/c/b6c46ab0bdee90c238e96ea4a74972118c97900d"}],"title":"ipmi: Remove all sysfs files on registration failure","x_generator":{"engine":"bippy-1.2.0"}}}}