7.8

CVE-2026-74363

bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs

In the Linux kernel, the following vulnerability has been resolved:

bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs

commit 4f375ade6aa9 ("bpf: Avoid RCU context warning when unpinning
htab with internal structs") moved inode cleanup from ->free_inode()
into ->destroy_inode() to avoid sleeping in RCU context when calling
bpf_any_put(). However this removed the RCU delay on freeing the
inode itself and the cached symlink body (i_link), both of which
can be accessed by RCU pathwalk (pick_link, may_lookup etc.).

This causes a use-after-free when a concurrent unlinkat() drops the
last inode reference and destroy_inode() frees the inode immediately,
while another task is still walking the path in RCU mode and reads
inode->i_opflags (offset +2) inside current_time() -> is_mgtime().

KASAN reports:
  BUG: KASAN: slab-use-after-free in is_mgtime include/linux/fs.h:2313
  Read of size 2 at addr ffff8880407e4282 (offset +2 = i_opflags)

The rules (per Al Viro):
  ->destroy_inode()  called immediately, can sleep, use for blocking
                     cleanup e.g. bpf_any_put()
  ->free_inode()     called after RCU grace period, use for freeing
                     inode and anything RCU-accessible e.g. i_link

Fix: split the two concerns properly:
  - keep bpf_any_put() in bpf_destroy_inode() since it is blocking
    and needs to run promptly
  - introduce bpf_free_inode() to handle kfree(i_link) and
    free_inode_nonrcu() with proper RCU delay, preventing the UAF
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version e28616ca3d67e745ecb2f10eba4a626e1fc9a203
Version < ea1c243c39e32b7fc1c2edfe32081ff7e30a877c
Status affected
Version 743a620c661994c7f0938e6dd32fb0883fb1e0ea
Version < 5fecb71c10c28aef276ba49c718dc961745fdcf0
Status affected
Version b6e9645be9eb93f7aff3ca887f8edb6f1d63358f
Version < c70d0f9114c3cc156f6029a400c4eb7e6f7c82b2
Status affected
Version ee04cff9ed4d6bb25802f5cecfcd0750500410f3
Version < 53649846e0437d1d9b7cb993cfe54c367addf7ae
Status affected
Version 4f375ade6aa9f37fd72d7a78682f639772089eed
Version < 61f19729728243c82476dee31315143ed3275e7f
Status affected
Version 4f375ade6aa9f37fd72d7a78682f639772089eed
Version < 0497ff765746d9b2d17445c8f7cc737b36c0152a
Status affected
Version 4f375ade6aa9f37fd72d7a78682f639772089eed
Version < b93c55b4932dd7e32dca8cf34a3443cc87a02906
Status affected
Version de2d2baecc84cc7fca52eec2b9b55d89c93e3565
Status affected
Version 5.15.195
Version < 5.15.212
Status affected
Version 6.1.157
Version < 6.1.178
Status affected
Version 6.6.113
Version < 6.6.145
Status affected
Version 6.12.54
Version < 6.12.97
Status affected
Version 6.17.4
Version < 6.18
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.026
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ea1c243c39e32b7fc1c2edfe32081ff7e30a877c
https://git.kernel.org/stable/c/5fecb71c10c28aef276ba49c718dc961745fdcf0
https://git.kernel.org/stable/c/c70d0f9114c3cc156f6029a400c4eb7e6f7c82b2
https://git.kernel.org/stable/c/53649846e0437d1d9b7cb993cfe54c367addf7ae
https://git.kernel.org/stable/c/61f19729728243c82476dee31315143ed3275e7f
https://git.kernel.org/stable/c/0497ff765746d9b2d17445c8f7cc737b36c0152a
https://git.kernel.org/stable/c/b93c55b4932dd7e32dca8cf34a3443cc87a02906