CVE-2026-64015

Summary

In the Linux kernel, the following vulnerability has been resolved:

security/keys: fix missed RCU read section on lookup

Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() code really is designed around removing the node from the tree and then freeing it after an RCU grace-period.

The regular key handling doesn't see this because holding the keyring semaphore hides any lifetime issues, but the persistent key handling uses a different model.

Instead of extending the keyring locking, just do the simple RCU locking that the assoc_array was designed for.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb2a4df200d570b2c33a57e1ebfa5896e4bc81b69 < 4c5d407ba3ff7f30561ff73ba1b07ed70c864edcaffected
LinuxLinuxb2a4df200d570b2c33a57e1ebfa5896e4bc81b69 < cefa4265b11176c897a7d9e8e54d89e3701c5584affected
LinuxLinuxb2a4df200d570b2c33a57e1ebfa5896e4bc81b69 < 5659e6923cb72f8e18e8b539109ab512455fe195affected
LinuxLinuxb2a4df200d570b2c33a57e1ebfa5896e4bc81b69 < 50bb3435a5e627bfbdc52eb4536f49f88b3486b8affected
LinuxLinuxb2a4df200d570b2c33a57e1ebfa5896e4bc81b69 < 66288dcadf80974436250e9f70ed848836b835b5affected
LinuxLinuxb2a4df200d570b2c33a57e1ebfa5896e4bc81b69 < 43a1e3744548e6fd85873e6fb43e293eb4010694affected
LinuxLinux3.13affected
LinuxLinux0 < 3.13unaffected
LinuxLinux6.1.175 <= 6.1.*unaffected
LinuxLinux6.6.142 <= 6.6.*unaffected
LinuxLinux6.12.92 <= 6.12.*unaffected
LinuxLinux6.18.34 <= 6.18.*unaffected
LinuxLinux7.0.11 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References