CVE-2026-80995
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mctp: hold a reference to the route device in mctp_route_lookup()
mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addrs. mctp_dev_saddr() then reads rt->dev->addrs[0], giving a use-after-free reachable by an unprivileged local AF_MCTP user on the receive/forwarding path (no CAP_NET_RAW required):
BUG: KASAN: slab-use-after-free in mctp_route_lookup Read of size 1 at addr … by task mctp_uaf/… mctp_route_lookup mctp_pkttype_receive Freed by task …: kfree mctp_dev_put mctp_dev_notify
In the same window mctp_dst_from_route() -> mctp_dev_hold() also increments a refcount that has already reached zero ("refcount_t: addition on 0 … mctp_dev_hold").
This reintroduces the use-after-free class of CVE-2023-3439: the source address lookup was moved ahead of the point where the destination takes its device reference.
Take a reference with refcount_inc_not_zero() before touching rt->dev, skip a device that is already dead, and drop the reference once the destination has taken its own.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 22cb45afd221b9e4f2a1dcc74a8ff645b7293aa1 < cc561f8af25586300c2f9d285babb163b866b293 | affected |
| Linux | Linux | 22cb45afd221b9e4f2a1dcc74a8ff645b7293aa1 < 408da1df18116c971c3392e21e50586688cd3fbf | affected |
| Linux | Linux | 7.1 | affected |
| Linux | Linux | 0 < 7.1 | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/cc561f8af25586300c2f9d285babb163b866b293
- https://git.kernel.org/stable/c/408da1df18116c971c3392e21e50586688cd3fbf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.