9.8
CVE-2026-74434
- EPSS 0.34%
- Veröffentlicht 15.08.2026 05:59:33
- Zuletzt bearbeitet 17.08.2026 06:19:39
- CVE-Watchlists
- Unerledigt
rxrpc: Don't move a peeked OOB message onto the pending queue
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto the pending queue rxrpc_recvmsg_oob() takes a received oob message off recvmsg_oobq and, if a response is needed, moves it onto the pending_oobq tree. However, only the unlink from recvmsg_oobq is guarded by MSG_PEEK; the move onto pending_oobq always runs. As a result, reading a challenge with MSG_PEEK leaves the skb on recvmsg_oobq while also adding it to pending_oobq. Since struct sk_buff's rbnode shares storage with its next and prev pointers, rb_insert_color() overwrites the list linkage, and the skb, which holds a single reference, becomes reachable from both queues at once. When the socket is closed both queues are drained in turn. While draining recvmsg_oobq, __skb_unlink() follows the next and prev pointers that rbnode has overwritten and writes to a bad address. Also, as the skb holds a single reference but is freed from each queue, both the skb and the connection reference it holds are released twice. This leads to memory corruption and to a use-after-free caused by the connection refcount underflow. MSG_PEEK does not consume the message from the queue, so only unlink it from recvmsg_oobq and then move it onto pending_oobq or free it when the message is actually consumed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
5800b1cf3fd8ccab752a101865be1e76dac33142
Version <
9ada3931beb37068fcb725b34b0398457009f343
Status
affected
Version
5800b1cf3fd8ccab752a101865be1e76dac33142
Version <
5f470cc883416fea6d3bce18ef96bf91dd49ffc3
Status
affected
Version
5800b1cf3fd8ccab752a101865be1e76dac33142
Version <
5801cff7d5d7b4e9d877dfb627b23eb63167f02c
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.16
Status
affected
Version
0
Version <
6.16
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.272 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/9ada3931beb37068fcb725b34b0398457009f343
https://git.kernel.org/stable/c/5f470cc883416fea6d3bce18ef96bf91dd49ffc3
https://git.kernel.org/stable/c/5801cff7d5d7b4e9d877dfb627b23eb63167f02c