7.8

CVE-2026-74563

rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()

In the Linux kernel, the following vulnerability has been resolved:

rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()

rds_tcp_laddr_check() looks up a scoped IPv6 interface with
dev_get_by_index_rcu(), drops the RCU read-side lock, and only then
passes the bare struct net_device * into ipv6_chk_addr().

dev_get_by_index_rcu() only keeps the device alive within the same RCU
read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can
free the net_device; ipv6_chk_addr() then dereferences the stale pointer
in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading
freed memory.

Keep the RCU read-side lock held across the ipv6_chk_addr() call instead
of dropping it right after the lookup, so the device cannot be freed
while it is in use.

  BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
  Read of size 8 at addr ffff8880106ec000 by task exploit/153
  Call Trace:
   ...
   kasan_report (mm/kasan/report.c:595)
   __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)
   ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)
   rds_tcp_laddr_check (net/rds/tcp.c:370)
   rds_bind (net/rds/bind.c:248)
   __sys_bind (net/socket.c:1920)
   __x64_sys_bind (net/socket.c:1956)
   do_syscall_64 (arch/x86/entry/syscall_64.c:63)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < f8a8977af2134a1d91e5f9773cb7d9d53278c830
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < ba95bce5dfe6e2ef602a87e0557225f2934ccb5c
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < c4933624a6f416ecfcc31ab58d585da1207a0597
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < 76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < b1d480fce05f857dc438080cd8c9244b84a83494
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < 8398bc477d3cb3e2b018a5aaac2bec0f69acda30
Status affected
Version eee2fa6ab3225192d6d894c54a6fb02ac9efdff6
Version < 78f75d632f74b8de0f081a128588f7c37d0d1164
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.19
Status affected
Version 0
Version < 4.19
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef
https://git.kernel.org/stable/c/f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff
https://git.kernel.org/stable/c/b1d480fce05f857dc438080cd8c9244b84a83494
https://git.kernel.org/stable/c/8398bc477d3cb3e2b018a5aaac2bec0f69acda30
https://git.kernel.org/stable/c/78f75d632f74b8de0f081a128588f7c37d0d1164
https://git.kernel.org/stable/c/ba95bce5dfe6e2ef602a87e0557225f2934ccb5c
https://git.kernel.org/stable/c/c4933624a6f416ecfcc31ab58d585da1207a0597
https://git.kernel.org/stable/c/f8a8977af2134a1d91e5f9773cb7d9d53278c830