SB20260905103 - Use-after-free in Linux kernel ipv4
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80849)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access freed memory.
The vulnerability exists due to use-after-free in current_key handling in the TCP Authentication Option (TCP-AO) code when processing inbound TCP-AO traffic during a socket reconnect to a different peer. A local user can race inbound TCP-AO processing with reconnecting a socket to another peer to access freed memory.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2857dcbd03cf3354af0fba1b65c6a260fb43811a
- https://git.kernel.org/stable/c/73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3
- https://git.kernel.org/stable/c/84a93b4e012587d0a4a84ffb23ec6da18e9d85f9
- https://git.kernel.org/stable/c/da4471557f279d0f56605158a625bb6e49ef7d41
- https://git.kernel.org/stable/c/e54ad693eddb40c595add013f545354c538e325b