Use-after-free in Linux kernel - CVE-2026-45970
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the rlb_arp_recv function in the bonding ALB RX path when processing ARP messages during rapid bond up/down cycles. A local user can trigger concurrent bond up/down operations while ARP traffic is being received to cause a denial of service.
The issue is triggered by a race condition between rlb_arp_recv() and rlb_deinitialize().
How to mitigate CVE-2026-45970
Sources
- https://git.kernel.org/stable/c/c65cdf46ce340c9c00fbbaf84599d2daff43626e
- https://git.kernel.org/stable/c/d31065526f160ee0244a719230aa069daca2bf4d
- https://git.kernel.org/stable/c/db5435b5342e3aaa4521d0f3ccfe94316b253ca1
- https://git.kernel.org/stable/c/de7c097800f07f3c108185c7a38b53a530ba30ff
- https://git.kernel.org/stable/c/e6834a4c474697df23ab9948fd3577b26bf48656
- https://git.kernel.org/stable/c/f94a0de7b9f32745a14a1621c63087a092823587
- https://git.kernel.org/stable/c/fd54ddc929be1d6c3b3b7b35d6d4642a5d9e803c
- https://git.kernel.org/stable/c/fef13c403be3fb685cb06419e6b3623106aab5ba