SB2026072132 - Use-after-free in Linux kernel tipc
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-63801)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in tipc_aead_decrypt_done in the TIPC crypto subsystem when processing crafted encrypted frames during asynchronous decryption. A remote attacker can send crafted encrypted frames to trigger a read from freed memory and cause a denial of service.
Exploitation requires the asynchronous decryption path to be used and can occur while the associated network namespace is being torn down.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0a780653b2a7569a7af9be7d0b00b1251baca63a
- https://git.kernel.org/stable/c/171d31245d11bf84836fad3b394cb465a4d008ec
- https://git.kernel.org/stable/c/1eea5e1820a2f5164d706bd1277bc97ff31ce32d
- https://git.kernel.org/stable/c/2d1f21419ec121232c916d3a3fc9b6766473a0e7
- https://git.kernel.org/stable/c/bda3348872a2ef0d19f2df6aa8cb5025adce2f20
- https://git.kernel.org/stable/c/dca7713fe044a2067387948557ea099056e1679e
- https://git.kernel.org/stable/c/e18769616fd5a90ec1e12aabbba544c488284292
- https://git.kernel.org/stable/c/eaca7dae02fab70c8d223cffe03cec1b93249ce2