-
CVE-2026-72431
- EPSS 0.2%
- Veröffentlicht 15.08.2026 05:56:46
- Zuletzt bearbeitet 17.08.2026 06:19:10
- Erkennungen
alloc_tag: fix use-after-free in /proc/allocinfo after module unload
In the Linux kernel, the following vulnerability has been resolved:
alloc_tag: fix use-after-free in /proc/allocinfo after module unload
allocinfo_start() only reinitializes the codetag iterator at position 0.
For subsequent reads (position > 0), it reuses cached iterator state from
the previous batch. allocinfo_stop() drops mod_lock between read batches,
which allows module unload to complete and free the module memory that the
cached iterator still references:
CPU0 (read) CPU1 (rmmod)
---- ----
allocinfo_start(pos=0)
down_read(mod_lock)
allocinfo_show()
...
allocinfo_stop()
up_read(mod_lock)
codetag_unload_module()
kfree(cmod)
release_module_tags()
...
free_mod_mem()
allocinfo_start(pos=N)
down_read(mod_lock)
// reuses cached iter, skips re-init
allocinfo_show()
ct->filename <-- UAF
After free_mod_mem() frees the module's .rodata, allocinfo_show()
dereferences ct->filename, ct->function which point there.
Save the iterator state in allocinfo_next() and resume from it in
allocinfo_start() with codetag_next_ct(), which detects module removal via
idr_find() returning NULL and skips to the next module.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
9f44df50fee4d2f6cb374177244ccfa9f0a5cc95
Version <
37e3e8a2c3bfdd503209f043f8bbfbdcf5a1d92f
Status
affected
Version
9f44df50fee4d2f6cb374177244ccfa9f0a5cc95
Version <
008ceffd44040f809aead6d7bef7cb1210c4149a
Status
affected
Version
9f44df50fee4d2f6cb374177244ccfa9f0a5cc95
Version <
2956268efc457cb05d29c1bf94de1e8e684d7bbc
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.17
Status
affected
Version
0
Version <
6.17
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/37e3e8a2c3bfdd503209f043f8bbfbdcf5a1d92f
https://git.kernel.org/stable/c/008ceffd44040f809aead6d7bef7cb1210c4149a
https://git.kernel.org/stable/c/2956268efc457cb05d29c1bf94de1e8e684d7bbc