SB20260816304 - Use-after-free in Linux kernel sunrpc
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72222)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to a use-after-free in the sunrpc TLS handshake callback handling in svc_tcp_handshake() and svc_tcp_handshake_done() when a connection close overlaps an asynchronous TLS handshake. A remote attacker can trigger a connection close during the TLS handshake to cause memory corruption.
The issue is reachable on TLS-enabled NFS servers, and signal delivery during the interruptible wait can trigger the affected race window.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/083e9c2ec7e8bb13b79c9fd7b337abdd758ecc5f
- https://git.kernel.org/stable/c/2d4f97d13fff91e0bc539216be88b884b544d49f
- https://git.kernel.org/stable/c/3f9ee75a97a769be258784c22b89657acb5ed9bd
- https://git.kernel.org/stable/c/4f988f3a2808fb659f3880c282041ff067acad78
- https://git.kernel.org/stable/c/f3b55945dd99f29d83e1965d0141040a35262346